HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-39597Published Modified CNA Patchstack

CVE-2026-39597: WordPress WPZOOM Addons for Elementor plugin <= 1.3.4 - Reflected Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WPZOOM Addons for Elementor <= 1.3.4 versions.

Metrics

CVSS v3.1
7.1
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Reflected Cross-Site Scripting (XSS) in WPZOOM Addons for Elementor (versions 1.3.4 and below) allows an unauthenticated remote attacker to inject malicious scripts into a victim's browser session. The vulnerability is reachable over the network and requires no login, but does require tricking a user into clicking a crafted link. Successful exploitation lets the attacker execute arbitrary JavaScript in the victim's browser context, enabling session hijacking, credential theft, or page content manipulation. HarborGuard is tracking this advisory and will make a patched-image rebuild available as soon as an upstream fix is published.

HarborGuard Coverage

Detection

Detection for CVE-2026-39597 is available across every HarborGuard environment. The CVE is ingested from upstream feeds (including Patchstack) within minutes of publication and matched against customer images and pipelines, including custom-built images that bundle this plugin.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 7.1 (HIGH) and applying per-environment compliance policy weighting to determine urgency and routing. Findings are surfaced to the appropriate team inbox within each customer organization based on configured alert rules.

Available
Patch

Because no fix version has been published upstream, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment the vendor ships a corrected release. In the interim, customers can apply compensating controls using HarborGuard's policy engine to flag or block any image containing the affected plugin version.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the malicious payload over the network by sending the victim a crafted URL pointing to the vulnerable WordPress site.

  • AuthenticationNot required

    No account or credentials are needed; the vulnerability is exploitable by any unauthenticated party.

  • Victim interactionRequired

    A victim must click or follow a specially crafted link, making this a social-engineering-dependent attack.

  • Attack complexityDetail

    Exploitation is straightforward and condition-free once a victim opens the crafted link; no race conditions or special environment state are required.

Blast Radius

  • Attacker executes arbitrary JavaScript in the victim's browser session, enabling theft of session cookies and authentication tokens.
  • Attacker can read or exfiltrate any page content visible to the victim, including form inputs and displayed user data.
  • Attacker can modify the rendered page to serve fake login forms or redirect the victim to attacker-controlled sites.
  • With Limited impact on availability, the attacker can disrupt the victim's browsing session or cause client-side errors that degrade page functionality.

How HarborGuard Handles This

Available on HarborGuard: because no upstream fix exists for CVE-2026-39597 at this time, the platform monitors the Patchstack advisory on every ingest cycle and will trigger an automatic patched-image rebuild the moment a fix version is released. While awaiting a patch, customers can use HarborGuard's policy controls to flag or reject any image bundling WPZOOM Addons for Elementor at version 1.3.4 or below, enforcing a break-the-build gate in CI pipelines. Additional compensating controls worth considering include network-policy restrictions that limit which services can load arbitrary external scripts, and egress filtering to block outbound requests to unknown domains initiated from WordPress application containers. For customers with auto-remediation enabled, a rebuilt image, regression-test run, and a PR opened against affected workloads will be triggered automatically once the upstream fix is available.

See how HarborGuard automates this
Affected packages
  • WPZOOM / WPZOOM Addons for Elementor
    ≤ 1.3.4
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
References