CVE-2024-1171
Description
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery Widget in all versions up to, and including, 5.9.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Stored XSS in Essential Addons for Elementor Filterable Gallery Widget allows contributor-level attackers to inject arbitrary scripts.
Vulnerability
The Essential Addons for Elementor plugin for WordPress (versions up to and including 5.9.8) contains a stored cross-site scripting vulnerability in the Filterable Gallery Widget. Insufficient input sanitization and output escaping allow authenticated users with contributor-level or higher permissions to inject arbitrary web scripts. [1]
Exploitation
An attacker must have a WordPress account with at least contributor-level permissions. They can create or edit a post/page containing the Filterable Gallery Widget and inject malicious script code into the widget's settings. When any user (including administrators) views the affected page, the script executes. [1]
Impact
Successful exploitation leads to stored XSS, enabling the attacker to execute arbitrary JavaScript in the context of the victim's browser. This can result in session hijacking, defacement, or redirection to malicious sites. The attack is persistent and affects all visitors to the compromised page. [1]
Mitigation
The vulnerability is fixed in version 5.9.9 of the plugin, as indicated by the changeset [2]. Users should update to version 5.9.9 or later immediately. No workaround is available. The plugin is actively maintained and not listed on CISA's Known Exploited Vulnerabilities catalog as of publication. [2]
AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:*Range: <5.9.9
- Range: <=5.9.8
Patches
1r3034127Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.