WordPress Plugin Vulnerabilities

Sina Extension for Elementor 3.7.1 - 3.10.3 - Contributor+ Stored XSS via Table Widget

Description

The plugin does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Dmitrii Ignatyev
Submitter
Dmitrii Ignatyev
Verified
Yes

Timeline

Publicly Published
2026-09-07 (about 2 days ago)
Added
2026-09-07 (about 1 day ago)
Last Updated
2026-09-07 (about 1 day ago)

Other