Premium Addons for Elementor – AI-Ready Elementor Addons, Widgets & Templates <= 4.11.110 - Authenticated (Contributor+) Stored Cross-Site Scripting via Google Maps Widget Cluster Icon

Medium 6.4 CWE-79Fixed in 4.11.111
ID
WPSEC-2026-0765
Plugin
Premium Addons for Elementor – AI-Ready Elementor Addons, Widgets & Templates (premium-addons-for-elementor)
Affected
all versions before 4.11.111
Remediation
Update to 4.11.111 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Weakness
CWE-79
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-11
Attack surface
Premium Addons for Elementor – AI-Ready Elementor Addons, Widgets & Templates on WPSec AttackSurface
Fix released
Published

Description

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget's cluster icon setting in all versions up to, and including, 4.11.110 due to insufficient input sanitization and the unsafe insertion of the icon URL into the page with innerHTML. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0