The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is specifically triggered when an administrator or higher-privileged user opens the affected post in the Elementor editor, as the raw unescaped output occurs via the print_template() method registered on the 'elementor/section/print_template' hook rather than on the public-facing frontend.
We have discovered 108,324 live websites that are affected by CVE-2026-12141.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 108,324 live websites (100% of Premium Addons for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 428 versions ( 100% of all versions) |
| 30,550 websites | |
| 11,768 websites | |
| 7,499 websites | |
| 4,792 websites | |
| 4,727 websites | |
| 3,586 websites | |
| 3,465 websites | |
| 3,420 websites | |
| 2,664 websites | |
| 2,593 websites |
| .com | 45,097 websites |
| .de | 7,264 websites |
| .org | 5,224 websites |
| .com.br | 4,397 websites |
| .fr | 3,848 websites |
| .co.uk | 2,661 websites |
| .it | 2,609 websites |
| .nl | 2,268 websites |
| .pl | 2,045 websites |
| .net | 1,927 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | *,*** | ||
| *********.com | *,*** | ||
| *********.com | *,*** | ||
| ********.org | *,*** | ||
| ******************.org | *,*** | ||
| ********.com | *,*** | ||
| ****************.com | **,*** | ||
| ********.ca | **,*** | ||
| ********.**.il | **,*** | ||
| *********.gr | **,*** |
FAQ