A vulnerability was found in brainstormforce Ultimate Addons for Elementor Plugin up to 2.9.1 on WordPress and classified as problematic. This affects the function
wp_kses_post of the component Navigation Menu Widget. Such manipulation of the argument data-toggle-icon/data-close-icon leads to cross site scripting.
This vulnerability is traded as CVE-2026-15787. The attack may be launched remotely. There is no exploit available.