Back to overview

CVE-2026-14190

MEDIUM Exploitation: PoC
6.1
CVSS 3.1
Description
The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request.

Metadata

CVE ID
CVE-2026-14190
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-30 08:28 UTC
Published
2026-07-27 06:00 UTC
Last updated
2026-07-27 16:13 UTC
Primary CWE
CWE-79
CWE-79 Improper Neutralization of Input During Web Page Gene…
Vendor / Product
Unknown / Sina Extension for Elementor
Sources
cve.org  ·  NVD

Severity & Metrics

6.1 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
Unknown Sina Extension for Elementor — 0 < 3.10.2
Weakness (CWE)
CWESourceDescription
— cna CWE-79 Cross-Site Scripting (XSS)
CWE-79 adp CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.1 MEDIUM 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Back to overview