SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-13393

LOW · CVSS 3.5 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The ElementsKit Elementor Addons plugin for WordPress prior to version 3.10.01 is vulnerable due to inadequate sanitization and escaping of megamenu settings, allowing administrative users to store malicious JavaScript. This flaw can lead to stored Cross-Site Scripting (XSS) attacks, potentially affecting the sessions of Super Admins and site visitors on multisite networks. WordPress site administrators, particularly those managing multisite installations, should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-13393
Severity
LOW
CVSS
3.5
EPSS
0.14%
WordPress Java

Original NVD Description

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.