---
id: CVE-2026-92249
title: >-
  The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected
  Cross-Site Scripting via the 's' parameter in all versions up to, and
  including, 1.11 due to insufficient input sanitization and output escaping
summary: >-
  The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected
  Cross-Site Scripting via the 's' parameter in all versions up to, and
  including, 1.11 due to insufficient input sanitization and output escaping.
  This makes it p…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: qodeinteractive
product: Qi Addons For Elementor
affected:
  - qi_addons_for_elementor <= 1.11
published: '2026-09-18'
updated: '2026-09-19'
sourceUpdated: '2026-09-19T15:17:07.987'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92249'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/qi-addons-for-elementor/tags/1.11/assets/js/main.js#L3185
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/qi-addons-for-elementor/tags/1.11/assets/js/main.js#L3263
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3698642%40qi-addons-for-elementor&new=3698642%40qi-addons-for-elementor
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/d623d4d6-2d76-4b4e-bd8b-69fe6ae352ca?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00368
epssPercentile: 0.28078
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:22:00.894062Z'
ingestedAt: '2026-09-18T08:38:04.106Z'
---

## Overview

The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Table of Contents widget to be placed on a template that renders on the WordPress search-results page (e.g., a sitewide header or footer template) with the 'Limit ToC to Main Page Content' option left at its default value of No, so the widget scans the search-results heading that reflects the unsanitized `s` parameter.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
