LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-11767

Published
CVSS8.8
Severityhigh
WeaknessCWE-79
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputting them in the admin dashboard, allowing unauthenticated attackers to perform Stored Cross-Site Scripting attacks that execute when a logged-in administrator views the form submissions.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-11767

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-11767.