PT-2026-95299 · WordPress · Qi Addons For Elementor

·

CVE-2026-92249

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Qi Addons For Elementor versions prior to 1.12
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting. This occurs when the Table of Contents widget is placed on a template that renders on the WordPress search-results page, such as a sitewide header or footer, and the 'Limit ToC to Main Page Content' option is set to No. Under these conditions, the widget scans the search-results heading which reflects the unsanitized s parameter, enabling the injection of arbitrary web scripts that execute when a user accesses the affected page.
Recommendations Update Qi Addons For Elementor to version 1.12 or later. As a temporary mitigation, enable the 'Limit ToC to Main Page Content' option or remove the Table of Contents widget from templates that render on the search-results page.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92249

Affected Products

Qi Addons For Elementor