CVE-2026-4655 is a Stored Cross-Site Scripting vulnerability affecting the Element Pack Addons for Elementor WordPress plugin in versions 8.4.2 and earlier. The flaw exists in the SVG Image Widget's render_svg() function, which fetches remote SVG content and renders it without proper sanitization, allowing attackers to inject malicious JavaScript through SVG event handlers. The vulnerability carries a CVSS 3.1 score of 6.4 (Medium severity) with a network-based attack vector requiring low complexity. Exploitation requires authenticated access at the Contributor level or above, but does not require user interaction. The impact is limited to confidentiality and integrity compromise with no availability impact; however, the scope is changed, meaning the vulnerability can affect resources beyond the vulnerable component. Exploitation status indicates this threat is not currently active in the wild. There is no public exploit code available, and the vulnerability has not been designated as a Known Exploited Vulnerability by CISA. Community attention appears minimal, as reflected by the very low EPSS score of 0.00039, suggesting this vulnerability poses a lower prioritization risk compared to the broader CVE landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Bdthemes | Element Pack – Widgets, Templates & Addons For Elementor | >= 0, <= 8.4.2CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.