CVE

CVE-2026-13393 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.10.01

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-13393 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.10.01 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 3.10.01 3.10.01 2026-07-14

CVE-2026-13393

ElementsKit Elementor Addons versions prior to 3.10.01 are vulnerable to Cross-Site Scripting due to insufficient sanitization and escaping of megamenu menu-item settings, which can be exploited by users with administrative privileges to inject malicious JavaScript. In a multisite setup, this allows a non-super subsite Administrator, lacking the unfiltered_html capability, to plant a stored XSS payload that can be executed by the network Super Admin and other site visitors.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.