PT-2026-57062 · WordPress · The Plus Addons For Elementor

·

CVE-2026-15285

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Plus Addons for Elementor versions prior to 6.4.12
Description Authenticated users with Contributor level permissions or higher can execute a Stored Cross-Site Scripting attack. The issue occurs because the render() function in modules/widgets/tp button.php processes the custom attributes variable using the tp senitize js input() filter, which can be bypassed to inject malicious scripts.
Recommendations Update to version 6.4.12.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15285

Affected Products

The Plus Addons For Elementor