CVE-2026-6127Disclosure

LOWCVSS 6.4 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to, and including, 4.0.4. This is due to insufficient input sanitization when processing form-encoded REST API requests. The plugin registers the _elementor_data meta field with show_in_rest but omits a sanitize_callback, relying instead on a rest_pre_insert_post filter (sanitize_post_data function) that only sanitizes JSON-encoded request bodies. When a contributor sends a form-encoded PATCH request to the WordPress REST API, the json_decode() call on the raw body returns null, causing all sanitization to be skipped. The unsanitized data is then stored via update_post_meta() and later output without escaping through multiple widget sinks including the HTML widget's print_unescaped_setting() function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-05-01); latest day: 2
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-05-01: 2Mentions · 2026-05-11: 1Mentions · 2026-05-29: 2PoC Mentioned / Linked · 2026-05-11: 1Technical Details · 2026-05-01: 2Technical Details · 2026-05-11: 1Technical Details · 2026-05-29: 205-0105-1105-29
Signal classification2 categories
Disclosure
480.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-012
Disclosure2
2026-05-111
PoC1
2026-05-292
Disclosure2
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. Two Encodings, One Sanitiser: CVE-2026-6127 Turns Any WordPress Contributor Into Admin on Sites Running Elementor ≤ 4.0.4

    Post summary

    The tweet announces CVE‑2026‑6127, noting that it can elevate WordPress contributors to admin on Elementor sites up to version 4.0.4, but provides no PoC, exploit, or patch details.

    1000047
    231 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6127 Stored Cross-Site Scripting in Elementor Website Builder Plugin for WordPress 4.0.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6127

    Post summary

    A stored cross‑site scripting vulnerability in Elementor Website Builder Plugin version 4.0.4 (CVE‑2026‑6127) is reported, but no exploit, patch, or active exploitation details are provided.

    00100104
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6127 The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _elementor_data meta field in versions up to, and including, 4.0… https://www.cve.org/CVERecord?id=CVE-2026-6127

    Post summary

    The statement identifies CVE‑2026‑6127 as a stored XSS flaw in Elementor’s _elementor_data meta field, affecting versions up to 4.0. No PoC, exploit, patch, or active attack evidence is provided.

    00010130
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/2026-05-02-elementor-cve-2026-6127-rest-form-encoded-bypass-stored-xss #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link appears to announce a newly disclosed Elementor vulnerability (CVE‑2026‑6127) that enables stored XSS via a REST form encoded bypass.

    0000032
    231 followersView on X
  • N45HT@N45HTOfficial
    PoC

    CVE-2026-6127: Elementor REST API Stored XSS 👾💥​ 👨‍💻 CryptoCat (x/_CryptoCat) 🔗 https://cryptocat.me/blog/research/analysis/cve_2026_6127/ https://t.co/QgwX0U6yx2

    Post summary

    The tweet points to a research blog discussing a stored XSS vulnerability (CVE‑2026‑6127) in Elementor’s REST API, implying a proof‑of‑concept is available.

    0000058
    86 followersView on X

Explore more