CVE-2026-12141

Premium Addons for Elementor <= 4.11.84 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'premium_tooltip_text' Parameter

The Premium Addons for Elementor – Powerful Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'premium_tooltip_text' parameter in all versions up to, and including, 4.11.84 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is specifically triggered when an administrator or higher-privileged user opens the affected post in the Elementor editor, as the raw unescaped output occurs via the print_template() method registered on the 'elementor/section/print_template' hook rather than on the public-facing frontend.


We have discovered 108,324 live websites that are affected by CVE-2026-12141.

Run a Free Instant Scan




Affected Software

Product  Premium Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains108,324 live websites (100% of Premium Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 4.11.84
Vulnerable Versions Count428 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 11, 2026
  • Updated - Jul 14, 2026

Credits

  • Chloe Chamberland (finder)
  • PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-12141
United States30,550 websites



Germany11,768 websites
France7,499 websites
Brazil4,792 websites
GB4,727 websites
Italy3,586 websites
India3,465 websites
Spain3,420 websites
Poland2,664 websites
Netherlands2,593 websites

Website Distribution by TLD

Number of websites using CVE-2026-12141
.com45,097 websites
.de7,264 websites
.org5,224 websites
.com.br4,397 websites
.fr3,848 websites
.co.uk2,661 websites
.it2,609 websites
.nl2,268 websites
.pl2,045 websites
.net1,927 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12141

Top websites that are affected by CVE-2026-12141. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
*********.com Israel*,***
*********.com United States*,***
********.org United States*,***
******************.org United States*,***
********.com Canada*,***
****************.com United States**,***
********.ca Canada**,***
********.**.il Israel**,***
*********.gr Greece**,***
See full domain list

FAQ

CVE-2026-12141 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Premium Addons for Elementor
A total of 108,324 websites have been identified as vulnerable to CVE-2026-12141, based on global website indexing conducted by WebTechSurvey.
The Premium Addons for Elementor is affected by the CVE-2026-12141 vulnerability.
Premium Addons for Elementor versions up to and including 4.11.84 are vulnerable to CVE-2026-12141.