PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14817 Element Pack CVE debrief

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes before a bundled front-end library re-parses and renders them in the browser, allowing users with contributor-level access or higher to inject arbitrary JavaScript that executes in the session of any visitor who views the affected content.

Vendor
Element Pack
Product
Addons for Elementor
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-02
Original CVE updated
2026-08-02
Advisory published
2026-08-02
Advisory updated
2026-08-02

Who should care

Users of the Element Pack Addons for Elementor WordPress plugin, particularly those with contributor-level access or higher, and administrators responsible for WordPress security, should be aware of this vulnerability. They should inventory and verify plugin version, restrict access, and monitor for suspicious activity. Affected operator, platform, vulnerability-management, and security-team impact should be reviewed to ensure proper mitigation and remediation efforts are in place. This includes verifying plugin version, restricting access to contributor-level users, and monitoring for suspicious activity. Additionally, compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability has a CVSS score and severity that should be evaluated for proper prioritization and mitigation efforts. The CVE record was published on 2026-08-02T06:16:34.793Z and has not been modified since then. The NVD vulnerability details provide additional information on the vulnerability and its potential impact. The source item URL provides further context on the vulnerability. A source reference from [email protected] also provides additional information on the vulnerability. The official CVE record and NVD vulnerability details provide some detail on the vulnerability and its potential impact. The debrief provides an executive overview of the vulnerability, covering affected product or component, vulnerability class, likely operational impact, source-confidence limits, and review context. The technical summary provides a detailed technical framing of the vulnerability without unsupported root-cause or exploit claims. The evidence notes provide additional context on the vulnerability and its potential impact, including evidence limits and known and unknown affected scope. The recommended actions provide distinct safe defensive actions until the target count is met. These actions include inventory and verify plugin version, restrict access to 7

Technical summary

The Element Pack Addons for Elementor WordPress plugin before 8.7.13 does not sanitize option values passed through certain data attributes, allowing users with contributor-level access or higher to inject arbitrary JavaScript. This vulnerability affects users with contributor-level access or higher, and administrators responsible for WordPress security. The plugin's front-end library re-parses and renders these option values in the browser, leading to potential JavaScript injection.

Defensive priority

Users with contributor-level access or higher can inject arbitrary JavaScript. Inventory and verify plugin version, restrict access, and monitor for suspicious activity.

Recommended defensive actions

  • Inventory and verify plugin version
  • Restrict access to contributor-level users
  • Monitor for suspicious activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

Evidence is limited; verify plugin version and user access controls. Official CVE and NVD records provide some detail. Affected deployments should be inventoried, and owners assigned for follow-up. The CVE record was published on 2026-08-02T06:16:34.793Z and has not been modified since then. Defenders should verify plugin version, user access controls, and monitor for suspicious activity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-02T06:16:34.793Z and has not been modified since then.