CVE-2026-13393
ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.
| Vendor | unknown |
| Product | elementskit elementor addons |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown elementskit elementor addons
Be the first to know when new unknown vulnerabilities affecting unknown elementskit elementor addons are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / ElementsKit Elementor Addons
0 < 3.10.01
References
Credits
Revanth Hari Narayana Matte WPScan