CVE-2026-13344
Received Received - Intake

Stored XSS in Essential Addons for Elementor Plugin

Vulnerability report for CVE-2026-13344, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: WPScan

Description

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
essential_addons essential_addons_for_elementor to 6.6.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Stored Cross-Site Scripting (XSS) flaw in the Essential Addons for Elementor plugin before version 6.6.10. It allows users with Contributor-level access or higher to inject malicious JavaScript by exploiting unvalidated HTML tag names in the Pricing Table widget's title. The injected script executes when the page is viewed, including during administrator previews.

Detection Guidance

Check the installed version of the Essential Addons for Elementor plugin. If it is below 6.6.10, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version details.

Impact Analysis

An attacker with Contributor-level access could inject JavaScript that runs when the page is viewed. This could lead to session hijacking, defacement, or theft of sensitive data like cookies or admin credentials. Administrators previewing posts are also at risk, potentially exposing their sessions.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations may face compliance breaches, fines, or legal consequences if exploited.

Mitigation Strategies

Update the Essential Addons for Elementor plugin to version 6.6.10 or later immediately. Remove or restrict Contributor-level access to untrusted users until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13344. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart