CVE-2026-14190
MEDIUMSina Extension for Elementor < 3.10.2 - Reflected XSS
Title source: cnaDescription
The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value reconstructed from request input in one of its unauthenticated AJAX handlers before reflecting it into the HTML response, allowing unauthenticated attackers to execute arbitrary JavaScript in the browser of anyone who triggers a crafted request.
References (1)
Core 1
Core References
Exploit exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/9b855913-a55e-469d-b3cd-324c31b0d4d8/
Scores
CVSS v3
6.1
EPSS
0.0016
EPSS Percentile
5.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (1)
None/Sina Extension for Elementor
< 3.10.2
Published
Jul 27, 2026
Tracked Since
Jul 27, 2026