CyberRota Analysis
AI-GeneratedThe ElementsKit Elementor Addons plugin for WordPress prior to version 3.10.01 is vulnerable due to inadequate sanitization and escaping of megamenu settings, allowing administrative users to store malicious JavaScript. This flaw can lead to stored Cross-Site Scripting (XSS) attacks, potentially affecting the sessions of Super Admins and site visitors on multisite networks. WordPress site administrators, particularly those managing multisite installations, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.