What is CVE-2026-14817?
The Element Pack Addons for Elementor plugin before version 8.7.13 fails to sanitize option values passed via data attributes, allowing users with contributor-level access or higher to inject arbitrary JavaScript when a bundled front-end library re-parses and renders them. Upgrade to the latest version to mitigate this stored XSS vulnerability.
Azərbaycanca: Element Pack Addons for Elementor WordPress plaginindəki boşluq (8.7.13 versiyasından əvvəl) data atributları vasitəsilə ötürülən seçim dəyərlərinin sanitizasiya edilməməsi səbəbindən contributor və daha yüksək səlahiyyətli istifadəçilərə JavaScript inyeksiyasına imkan verir. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What level of access is required to exploit CVE-2026-14817 in the Element Pack Addons for Elementor plugin?
Exploiting this vulnerability requires contributor-level access or higher.
What causes the CVE-2026-14817 vulnerability?
The vulnerability is caused by a failure to sanitize option values passed via data attributes.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.