AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-66688

MEDIUM · CVSS 6.5 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Ultimate Addons for Elementor versions up to 1.45.2 are vulnerable to a Contributor Cross Site Scripting (XSS) flaw, which could allow attackers to inject malicious scripts into web pages viewed by users. This vulnerability poses a medium risk as it can lead to unauthorized actions on behalf of users or data theft. Website administrators using these versions should prioritize patching to mitigate potential exploitation.

CVE
CVE-2026-66688
Severity
MEDIUM
CVSS
6.5
EPSS
0.14%

Original NVD Description

Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.