Cross-Site Scripting Vulnerability in HT Mega Addons for Elementor Plugin
CVE-2026-11895
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 September 2026
What is CVE-2026-11895?
The HT Mega Addons for Elementor plugin for WordPress has a vulnerability that allows stored cross-site scripting. This issue arises from inadequate input sanitization and output escaping within the 'display_options' setting of the Data Table feature. Authenticated users with contributor-level access and above can exploit this vulnerability to inject arbitrary web scripts into pages. These scripts execute whenever a user accesses the affected page, potentially leading to unauthorized access and data exposure.
Affected Version(s)
HT Mega Addons for Elementor β Elementor Widgets & Template Builder 0 <= 3.1.1