SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-12141

MEDIUM · CVSS 4.9 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-11 · Last synced 2026-08-10

CyberRota Analysis

AI-Generated

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in the 'premium_tooltip_text' parameter. This vulnerability allows authenticated users with contributor-level access and above to inject malicious scripts that execute when a higher-privileged user edits the affected post in the Elementor editor. WordPress site administrators and developers using this plugin should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-12141
Severity
MEDIUM
CVSS
4.9
EPSS
0.19%
WordPress

Original NVD Description

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is specifically triggered when an administrator or higher-privileged user opens the affected post in the Elementor editor, as the raw unescaped output occurs via the print_template() method registered on the 'elementor/section/print_template' hook rather than on the public-facing frontend.