CVE detail
CVE-2026-11614
The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
20 source links · newest first
- Wordfence Intelligence Weekly WordPress Vulnerability Report (June 22, 2026 to June 28, 2026)Wordfence
SMTP HD Quiz 2.2.0 - 2.2.1 - Cross-Site Request Forgery via Multiple AJAX Handlers 4.3 CVSS Rating 4.3 (Medium) CVE-ID CVE-2026-13422 Patch Status Patched Published Jun 26, 2026 Affected Software HD Quiz [hd-quiz] Researcher Wordfence PRISM More Details > Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator Majestic Support – The
vendorwww.wordfence.comJul 2, 2026, 6:34 PM - https://www.wordfence.com/threat-intel/vulnerabilities/id/0f78479f-8e28-4fa4-bf2b-eefedffa4d72?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/team/layout/frontend.php#L46plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/site-title/layout/frontend.php#L28plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/site-logo/layout/frontend.php#L35plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/promo-box/layout/frontend.php#L51plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/pricing/layout/frontend.php#L16plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/info-list/layout/frontend.php#L15plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/image-scroller/layout/frontend.php#L28plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/image-scroller/layout/frontend.php#L14plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/icon-box/layout/frontend.php#L28plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/icon-box/layout/frontend.php#L12plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/hot-spot/layout/frontend.php#L35plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/hero-slider/layout/frontend.php#L65plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/button/layout/frontend.php#L36plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/author-box/layout/frontend.php#L59plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/widgets/animated-link/layout/frontend.php#L21plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/trunk/inc/helper-functions.php#L778plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.7.3/widgets/image-scroller/layout/frontend.php#L8plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM - https://plugins.trac.wordpress.org/browser/xpro-elementor-addons/tags/1.7.3/inc/helper-functions.php#L1069plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgJun 24, 2026, 4:17 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-14856CVSS 6.3 · Medium
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization…
- CVE-2026-65764CVSS 5.1 · Medium
Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Commander 5.0.0-6.1.1 - Improper validation of user inputs lead to a reflective XSS vulnerability.
- CVE-2026-15928CVSS 8.2 · High
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.
- CVE-2026-17496CVSS 8.1 · High
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without…
- CVE-2026-15425CVSS 6.4 · Medium
The Yoast SEO – Advanced SEO with real-time guidance and built-in AI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Slug (post_name) in all versions up…
- CVE-2026-57531CVSS 5.1 · Medium
Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers to execute arbitrary JavaScrip…