CVE

CVE-2026-14817 — Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.7.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-14817 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 8.7.13 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 8.7.13 8.7.13 2026-08-02

CVE-2026-14817

The Element Pack Addons for Elementor WordPress plugin contains an issue where certain option values are not properly sanitized before being re-rendered by a bundled front-end library, enabling contributors and above to embed malicious JavaScript code that runs on visitors' browsers when they view related content. This vulnerability allows attackers to inject arbitrary client-side scripts without needing elevated privileges. The flaw affects versions prior to 8.7.13.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.