PT-2026-95299 · WordPress · Qi Addons For Elementor
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Qi Addons For Elementor versions prior to 1.12
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Reflected Cross-Site Scripting. This occurs when the Table of Contents widget is placed on a template that renders on the WordPress search-results page, such as a sitewide header or footer, and the 'Limit ToC to Main Page Content' option is set to No. Under these conditions, the widget scans the search-results heading which reflects the unsanitized
s parameter, enabling the injection of arbitrary web scripts that execute when a user accesses the affected page.Recommendations
Update Qi Addons For Elementor to version 1.12 or later.
As a temporary mitigation, enable the 'Limit ToC to Main Page Content' option or remove the Table of Contents widget from templates that render on the search-results page.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qi Addons For Elementor