rootpwn

medium · CVSS v3 6.4 · EPSS 0.00201

CVE-2026-8354

The Gum Addon for Elementor plugin for WordPress up to version 1.3.15 suffers from a Stored Cross-Site Scripting vulnerability in the 'pop_t

Overview

The Gum Addon for Elementor plugin for WordPress up to version 1.3.15 suffers from a Stored Cross-Site Scripting vulnerability in the 'pop_tag' parameter. Insufficient input sanitization and output escaping allow authenticated users with contributor-level access or higher to inject malicious scripts into pages. This script execution occurs whenever unsuspecting users access the compromised pages.

Description

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Impact

This vulnerability affects the integrity and confidentiality of the web application by allowing malicious script execution in the context of a victim's session. Authenticated attackers with low privileges (contributor-level) can leverage this flaw to hijack sessions, deface pages, or redirect users. Organizations utilizing the affected plugin face potential reputational damage and unauthorized actions performed on behalf of authenticated users.

Remediation

Update the Gum Addon for Elementor plugin to a version later than 1.3.15 as soon as a patched release is made available by the vendor. Restrict contributor-level access permissions to trusted users only as a defense-in-depth measure. Implement Web Application Firewall (WAF) rules to detect and block cross-site scripting patterns targeting the 'pop_tag' parameter.

Risk context

The vulnerability carries a CVSS v3 score of 6.4 (Medium), indicating a moderate level of severity. The EPSS score of 0.00201 suggests a relatively low current probability of exploitation in the wild, but defenders should still prioritize patching due to the authenticated attack vector.

Affected products

  • Gum Addon for Elementor plugin for WordPress

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
6.4
CVSS v4
EPSS
0.00201

wordpress xss stored-xss plugin-vulnerability elementor web-security

← All CVEs