
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22518 is a DOM-based Cross-Site Scripting (XSS) vulnerability in the "X Addons for Elementor" WordPress plugin developed by pencilwp. It affects all versions from n/a through 1.0.23 and was disclosed on January 8, 2026, with the CVE record received from Patchstack on the same date. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Patchstack (Patchstack, Red Hat CVE).
The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation) and manifests as DOM-based XSS, meaning malicious script execution occurs client-side within the browser's DOM rather than being reflected or stored server-side. An authenticated, low-privileged attacker can inject crafted input through the plugin's Elementor widget interface, which is then processed unsafely by client-side JavaScript, allowing arbitrary script execution in the victim's browser context. Exploitation requires user interaction (e.g., a victim visiting or previewing a page containing the malicious widget), and the scope is changed, indicating impact can extend beyond the originating page (Patchstack, Red Hat CVE).
Successful exploitation allows a low-privileged authenticated attacker to execute arbitrary JavaScript in the browsers of other users who view the affected page, potentially compromising session tokens, stealing credentials, performing unauthorized actions on behalf of victims, or defacing site content. The changed scope in the CVSS vector indicates that the impact can extend beyond the vulnerable plugin itself to affect the broader WordPress site and its users. Confidentiality, integrity, and availability are all assessed as having low impact, consistent with typical XSS exploitation scenarios (Patchstack).
No evidence of active in-the-wild exploitation or public proof-of-concept exploit code has been identified for this vulnerability. The EPSS score is approximately 0.033% (0.000330), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker with at least low-level privileges, which somewhat limits the attack surface compared to unauthenticated vulnerabilities (Red Hat CVE).
<img src=x onerror=alert(document.cookie)> or a more sophisticated payload targeting session tokens) into a vulnerable widget parameter./wp-admin/admin-ajax.php or Elementor save endpoints containing encoded JavaScript payloads.wp_postmeta table) containing <script>, onerror, javascript:, or similar XSS patterns in widget settings.Users should update the X Addons for Elementor plugin to version 1.0.24 or later, which contains the fix for this vulnerability. No configuration-based workaround is documented; the recommended remediation is to apply the patch immediately. Site administrators should also audit Elementor page content created by low-privileged users for any suspicious script injections prior to patching (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."