Lyrie.ai[verified]@lyrie_aiDisclosure
The tweet announces CVE‑2026‑6127, noting that it can elevate WordPress contributors to admin on Elementor sites up to version 4.0.4, but provides no PoC, exploit, or patch details.
Lyrie.ai[verified]@lyrie_aiDisclosure
The link appears to announce a newly disclosed Elementor vulnerability (CVE‑2026‑6127) that enables stored XSS via a REST form encoded bypass.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A stored cross‑site scripting vulnerability in Elementor Website Builder Plugin version 4.0.4 (CVE‑2026‑6127) is reported, but no exploit, patch, or active exploitation details are provided.
CVE@CVEnewDisclosure
The statement identifies CVE‑2026‑6127 as a stored XSS flaw in Elementor’s _elementor_data meta field, affecting versions up to 4.0. No PoC, exploit, patch, or active attack evidence is provided.
N45HT@N45HTOfficialPoC
The tweet points to a research blog discussing a stored XSS vulnerability (CVE‑2026‑6127) in Elementor’s REST API, implying a proof‑of‑concept is available.