The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. wp_kses_post, applied on save for users without unfiltered_html, does not neutralize HTML-entity-encoded payloads stored inside data-* attributes on kses-allowed elements, as the browser decodes these values client-side before jQuery .html() renders them as markup.
We have discovered 262,349 live websites that are affected by CVE-2026-15787.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 262,349 live websites (100% of Header Footer and Blocks for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 125 versions ( 100% of all versions) |
| 72,257 websites | |
| 24,292 websites | |
| 14,885 websites | |
| 12,100 websites | |
| 11,045 websites | |
| 9,780 websites | |
| 8,634 websites | |
| 8,263 websites | |
| 6,974 websites | |
| 6,747 websites |
| .com | 112,690 websites |
| .de | 12,923 websites |
| .org | 12,679 websites |
| .com.br | 8,951 websites |
| .co.uk | 6,494 websites |
| .fr | 6,471 websites |
| .nl | 6,216 websites |
| .it | 5,953 websites |
| .net | 5,453 websites |
| .pl | 5,136 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ************.net | *,*** | ||
| ******.com | *,*** | ||
| **********.org | *,*** | ||
| **********.com | *,*** | ||
| **********.com | *,*** | ||
| ***********************.de | **,*** | ||
| *******.co | **,*** | ||
| **************.org | **,*** | ||
| *******************.com | **,*** | ||
| **********.com | **,*** |
FAQ