PT-2026-25275 · Noor Alam · Magical Addons For Elementor

Abu Hurayra

·

Published

2026-03-13

·

Updated

2026-03-14

·

CVE-2026-32429

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Noor Alam Magical Addons For Elementor versions through 1.4.1
Description A flaw exists in Noor Alam Magical Addons For Elementor that allows for Stored Cross-site Scripting (XSS). This issue is due to improper neutralization of input during web page generation. The vulnerability could allow an attacker to inject malicious scripts into web pages viewed by other users. The vulnerable component is magical-addons-for-elementor.
Recommendations Versions prior to 1.4.1 should be updated.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-32429

Affected Products

Magical Addons For Elementor