CVE Database /
CVE-2026-13393
CVE
CVE-2026-13393 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.10.01
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-13393
|
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.10.01 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Unknown
|
< 3.10.01
|
3.10.01 |
2026-07-14 |
—
|
CVE-2026-13393
ElementsKit Elementor Addons versions prior to 3.10.01 are vulnerable to Cross-Site Scripting due to insufficient sanitization and escaping of megamenu menu-item settings, which can be exploited by users with administrative privileges to inject malicious JavaScript. In a multisite setup, this allows a non-super subsite Administrator, lacking the unfiltered_html capability, to plant a stored XSS payload that can be executed by the network Super Admin and other site visitors.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings