CVE-2026-13393
Received Received - Intake

Stored XSS in ElementsKit Elementor Addons WordPress Plugin

Vulnerability report for CVE-2026-13393, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: WPScan

Description

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpmet elementskit to 3.10.01 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stored Cross-Site Scripting (XSS) issue in the ElementsKit Elementor Addons WordPress plugin before version 3.10.01. It occurs because the plugin does not properly sanitize or escape certain megamenu menu-item settings before saving them or displaying them on the front end. Additionally, it does not require the unfiltered_html capability to save these settings.

Detection Guidance

Check if the ElementsKit Elementor Addons plugin version is below 3.10.01. Inspect WordPress admin capabilities for unfiltered_html access. Review stored megamenu settings for unsanitized JavaScript in the database.

Impact Analysis

An attacker with administrative access could exploit this to inject malicious JavaScript code. On a multisite network, a non-super subsite Administrator (who lacks unfiltered_html capability) could plant a stored XSS payload that executes when the network Super Admin or site visitors access the affected pages.

Compliance Impact

This vulnerability could lead to stored Cross-Site Scripting (XSS) attacks, potentially exposing sensitive user data. For GDPR, this may result in unauthorized data access or processing, violating Article 32 (security of processing). Under HIPAA, it could compromise protected health information if exploited in healthcare environments.

Mitigation Strategies

Update the ElementsKit Elementor Addons plugin to version 3.10.01 or higher. Remove any suspicious megamenu settings containing JavaScript. Restrict administrative capabilities to prevent unauthorized script storage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13393. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart