What is CVE-2026-15787?
CVE-2026-15787 is a Stored Cross-Site Scripting vulnerability in the Ultimate Addons for Elementor plugin for WordPress (versions up to 2.9.1). It allows authenticated attackers to inject malicious scripts via the Navigation Menu Widget's 'data-toggle-icon'/'data-close-icon' attributes due to insufficient input sanitization and output escaping. Users should update the plugin to the latest patched version.
Azərbaycanca: CVE-2026-15787, Elementor üçün Ultimate Addons plaginində (2.9.1-ə qədər versiyalar) 'Navigation Menu Widget' vasitəsilə Stored Cross-Site Scripting zəifliyidir. Bu boşluq 'data-toggle-icon'/'data-close-icon' atributlarında kifayət qədər input sanitization və output escaping olmaması səbəbindən autentifikasiya olunmuş istifadəçilərə zərərli skript yerləşdirməyə imkan verir. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which component of the Ultimate Addons for Elementor plugin is affected by CVE-2026-15787?
The vulnerability affects the plugin's Navigation Menu Widget, specifically exploited through the 'data-toggle-icon' and 'data-close-icon' attributes.
What should users do to protect themselves from CVE-2026-15787?
Users should immediately update the plugin to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.