CVE-2026-83541 PUBLISHED

Sina Extension for Elementor 3.7.1 - 3.10.3 - Contributor+ Stored XSS via Table Widget

Assigner: WPScan
Reserved: 31.08.2026 Published: 09.09.2026 Updated: 09.09.2026

The Sina Extension for Elementor WordPress plugin before 3.10.4 does not properly escape a Table widget setting before outputting it within an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

Product Status

Vendor Unknown
Product Sina Extension for Elementor
Versions Default: unaffected
  • affected from 3.7.1 to 3.10.4 (excl.)

Credits

  • Dmitrii Ignatyev finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE