Vulnerability in Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools — CVE-2026-62078
MediumSeverity
—Estimated exploit probability
600,000+ sitesInstalls
4.11.106Fixed in
What to do now
Update Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools to 4.11.106 or later.
Affected versions
- Everything up to and including 4.11.105
Affected: Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools (plugin, premium-addons-for-elementor)
What the vulnerability is
The Premium Addons for Elementor – AI-Ready Elementor Addons, Widgets & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.11.105. This is due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.