CVE-2026-39703 is a Stored Cross-Site Scripting (XSS) vulnerability in WPBITS Addons For Elementor Page Builder affecting versions 1.8.1 and earlier. The vulnerability exists in the plugin's improper neutralization of user input during web page generation, allowing attackers to inject and store malicious scripts within the application. This vulnerability can compromise WordPress installations that utilize this popular page builder extension. The vulnerability carries a CVSS 6.5 Medium severity rating with a network-based attack vector requiring low complexity and low privileges to execute. An attacker must have valid user authentication and user interaction to succeed, but once exploited, the attack has cross-site consequences affecting confidentiality, integrity, and availability for potential victims. The threat remains relatively contained due to authentication requirements, though the stored XSS nature allows for persistent impact. Exploitation of this vulnerability is currently not actively documented in public exploit databases, with no advisories indicating widespread exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities catalog, and community attention remains minimal based on its low EPSS score of 0.00034. Organizations using this plugin should apply security updates to version 1.8.2 or later, though immediate patching urgency is moderate given the lack of active exploitation evidence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.8.1CPE match | cpe:2.3:a:wpbits:wpbits_addons_for_elementor_page_builder:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.