在 BdThemes Element Pack Elementor 插件(bdthemes-element-pack-lite)中,存在网页生成期间输入中性化处理不当的漏洞(即“跨站脚本攻击”,Cross-site Scripting)。该漏洞允许执行存储型跨站脚本攻击(Stored XSS)。 受影响的产品为 Element Pack Elementor 插件,受影响版本范围从“不适用”(n/a)至 8.8.6。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| BdThemes | Element Pack Elementor Addons | 0 ~ 8.8.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105875 | 6.5 MEDIUM | WordPress Prime Slider – Addons For Elementor plugin <= 4.6.2 - Cross Site Scripting (XSS) |
| CVE-2026-105871 | 6.5 MEDIUM | WordPress Element Pack Elementor Addons plugin <= 8.8.6 - Cross Site Scripting (XSS) vulne |
No comments yet