CVE-2026-13393

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.
Configurations

No configuration.

History

31 Jul 2026, 18:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.5
CWE CWE-79

31 Jul 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-31 07:16

Updated : 2026-07-31 18:17


NVD link : CVE-2026-13393

Mitre link : CVE-2026-13393

CVE.ORG link : CVE-2026-13393


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')