CVE-2026-86788
HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag
CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th
The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the content is viewed, including by higher-privileged users who review or publish it.
| Vendor | unknown |
| Product | ht mega addons for elementor |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown ht mega addons for elementor
Be the first to know when new medium vulnerabilities affecting unknown ht mega addons for elementor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / HT Mega Addons for Elementor
3.2.0 < 3.2.6
References
Credits
Revanth Hari Narayana Matte WPScan