CVE-2026-22518: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-22518 is a DOM-based Cross-Site Scripting (XSS) vulnerability in the "X Addons for Elementor" WordPress plugin developed by pencilwp. It affects all versions from n/a through 1.0.23 and was disclosed on January 8, 2026, with the CVE record received from Patchstack on the same date. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium), assigned by Patchstack (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation) and manifests as DOM-based XSS, meaning malicious script execution occurs client-side within the browser's DOM rather than being reflected or stored server-side. An authenticated, low-privileged attacker can inject crafted input through the plugin's Elementor widget interface, which is then processed unsafely by client-side JavaScript, allowing arbitrary script execution in the victim's browser context. Exploitation requires user interaction (e.g., a victim visiting or previewing a page containing the malicious widget), and the scope is changed, indicating impact can extend beyond the originating page (Patchstack, Red Hat CVE).

Impact

Successful exploitation allows a low-privileged authenticated attacker to execute arbitrary JavaScript in the browsers of other users who view the affected page, potentially compromising session tokens, stealing credentials, performing unauthorized actions on behalf of victims, or defacing site content. The changed scope in the CVSS vector indicates that the impact can extend beyond the vulnerable plugin itself to affect the broader WordPress site and its users. Confidentiality, integrity, and availability are all assessed as having low impact, consistent with typical XSS exploitation scenarios (Patchstack).

Exploitability

No evidence of active in-the-wild exploitation or public proof-of-concept exploit code has been identified for this vulnerability. The EPSS score is approximately 0.033% (0.000330), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker with at least low-level privileges, which somewhat limits the attack surface compared to unauthenticated vulnerabilities (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the X Addons for Elementor plugin (version ≤ 1.0.23) using tools like WPScan or by inspecting page source for plugin indicators.
  2. Obtain low-privileged access: Register or log in as a low-privileged WordPress user (e.g., Contributor or Author role) on the target site.
  3. Craft malicious input: Create or edit an Elementor page/post using an X Addons widget, injecting a DOM-based XSS payload (e.g., <img src=x onerror=alert(document.cookie)> or a more sophisticated payload targeting session tokens) into a vulnerable widget parameter.
  4. Publish or share the page: Publish the page or share a preview link with a higher-privileged victim (e.g., Administrator).
  5. Victim triggers execution: When the victim visits or previews the page, the malicious JavaScript executes in their browser context, enabling session hijacking, credential theft, or further malicious actions (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated low-privileged users creating or editing Elementor pages with unusual script-like content in widget parameters; unexpected POST requests to /wp-admin/admin-ajax.php or Elementor save endpoints containing encoded JavaScript payloads.
  • File System: Unexpected modifications to Elementor page data in the WordPress database (wp_postmeta table) containing <script>, onerror, javascript:, or similar XSS patterns in widget settings.
  • Network: Outbound requests from victim browsers to attacker-controlled domains (e.g., for cookie exfiltration) originating from WordPress site pages; unusual redirects or beacon requests in browser network logs.
  • Process/Application: Browser console errors or unexpected JavaScript execution on pages containing X Addons for Elementor widgets; reports from users of unexpected pop-ups or redirects on affected pages.

Mitigation and workarounds

Users should update the X Addons for Elementor plugin to version 1.0.24 or later, which contains the fix for this vulnerability. No configuration-based workaround is documented; the recommended remediation is to apply the patch immediately. Site administrators should also audit Elementor page content created by low-privileged users for any suspicious script injections prior to patching (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management