Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.4

CVE-2026-15156: Essential Addons for Elementor <= 6.6.11 - Malicious Scripts on Your Site

CVE-2026-15156 CVE-2026-15156
Summary

A security flaw in the Essential Addons for Elementor plugin for WordPress allows attackers with some level of access to inject malicious code on your site. This can lead to unauthorized actions or data theft. To protect your site, update the plugin to the latest version.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
wpdevteam essential addons for elementor – popular elementor templates & widgets <= 6.6.11
Original title
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versio...
Original description
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Reading Progress Global Color Settings in all versions up to, and including, 6.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
mitre CVSS3.1 6.4
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 21 Jul 2026 · Updated: 21 Jul 2026 · First seen: 21 Jul 2026