CVE Explorer
CVE-2026-14817
The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Element Pack Addons for Elementor","vendor":"Unknown","versions":[{"lessThan":"8.7.13","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e545268db3452d9c362401a96aaf23040d3f36eddc7571d765b412fd98586bb6 · sha256:68ad5142d7e9e539… · /containers/cna/affected/0
CWE assertions
1 source assertion{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e545268db3452d9c362401a96aaf23040d3f36eddc7571d765b412fd98586bb6 · sha256:68ad5142d7e9e539… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/b2554df8-3083-41cf-8f62-04568ab3a9de/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e545268db3452d9c362401a96aaf23040d3f36eddc7571d765b412fd98586bb6 · sha256:68ad5142d7e9e539… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.