PT-2026-47639 · Elementor · Product Filter Widget For Elementor

·

CVE-2026-11603

·

Published

2026-06-09

·

Updated

2026-06-18

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Product Filter Widget for Elementor versions prior to 1.0.7
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to inject arbitrary web scripts. This is achieved via a CSRF-style form auto-submission to the 'admin-ajax.php' endpoint, which is registered via wp ajax nopriv without nonce verification or capability checks. The issue is triggered through the args[filterFormArray] parameter. Exploitation requires tricking a user into visiting an attacker-controlled page to execute the scripts.
Recommendations Update to a version later than 1.0.6.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11603

Affected Products

Product Filter Widget For Elementor