Skip to main content

Essential Addons for Elementor Stored XSS via Fancy Text Widget Allows Session Hijacking (CVE-2026-15145)

Scope: Essential Addons for Elementor WordPress Plugin Versions up to and Including 6.6.11

Severity: High

A stored cross-site scripting vulnerability in Essential Addons for Elementor, one of the most widely installed Elementor addon plugins with over 2 million active installations, allows authenticated attackers with contributor-level access to inject persistent malicious JavaScript through the Fancy Text Widget due to insufficient input sanitization and output escaping, with the injected payload executing automatically in the browser of any user who views the affected page including site administrators. Administrator-level payload execution enables silent creation of rogue admin accounts, plugin installation, and full site takeover without any further interaction. Organizations must update to Essential Addons for Elementor version 6.6.12 immediately, audit all contributor and author-level user accounts to confirm they belong to trusted individuals, and scan existing pages built with the Fancy Text Widget for injected script content.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.