XSS in Ultimate Addons for Elementor Nav Menu Widget (<=2.9.1)
CVE-2026-15787 Published on July 22, 2026
Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes
The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup.
Timeline
Vendor Notified
Disclosed 7 days later.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-15787 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-15787
Want to know whenever a new CVE is published for Brainstormforce Ultimate Addons For Elementor? stack.watch will email you.
Affected Versions
brainstormforce Ultimate Addons for Elementor:- Before and including 2.9.1 is affected.