What is CVE-2026-12231?
CVE-2026-12231 is a Stored Cross-Site Scripting (XSS) vulnerability in the Exclusive Addons for Elementor plugin for WordPress. It affects versions up to and including 2.7.9.8 via the 'exad_infobox_image' parameter due to insufficient input sanitization and output escaping, allowing authenticated attackers to inject malicious scripts. Update the plugin immediately.
Azərbaycanca: CVE-2026-12231 WordPress üçün Exclusive Addons for Elementor pluginində aşkarlanmış Stored Cross-Site Scripting (XSS) zəifliyidir. 'exad_infobox_image' parametri vasitəsilə 2.7.9.8 və əvvəlki versiyalara təsir edən bu boşluq autentifikasiya olunmuş hücumçulara zərərli skript yerləşdirməyə imkan verir. Plugin yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-12231?
The Exclusive Addons for Elementor plugin is affected.
Which parameter is targeted during the exploitation of CVE-2026-12231?
The 'exad_infobox_image' parameter is targeted.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.