Plus Addons for Elementor Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in the Plus Addons for Elementor plugin for WordPress. This issue affects versions through 6.4.11 and allows authenticated users with Contributor privileges or higher to inject malicious scripts. The vulnerability arises in the Button widget's 'custom_attributes' setting, where the 'render' function in 'modules/widgets/tp_button.php' improperly sanitizes the 'custom_attributes' string. The vulnerability has been patched in version 6.4.12.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Reproduction

To reproduce this vulnerability, an authenticated user with Contributor or higher privileges can add a Button widget and use the 'custom_attributes' setting to inject JavaScript. The injected script will be executed when the button is rendered.

Remediation

Users are advised to update the Plus Addons for Elementor plugin to version 6.4.12 or later.

Added: Jul 10, 2026, 5:49 AM
Updated: Jul 10, 2026, 5:49 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
1.7
exploitability
6.2
remediation
7.7
relevance
9.4
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.