Back to CVE List

CVE-2026-13393

Vulnerability Description

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
ElementsKit Elementor Addons

External References

Discussion (0)

Add Comment

No comments yet. Be the first!