Cross-Site Scripting Vulnerability in ElementsKit Elementor Addons by WordPress
CVE-2026-13393
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 31 July 2026
Badges
What is CVE-2026-13393?
The ElementsKit Elementor Addons for WordPress prior to version 3.10.01 contains a vulnerability that allows users with administrative privileges to execute stored Cross-Site Scripting (XSS) attacks. This flaw arises due to the failure to properly sanitize and escape certain settings related to megamenu menu items before storing and displaying them on the front end. In a multisite network, non-super subsite Administrators can exploit this vulnerability to inject malicious JavaScript, which can execute in the sessions of Super Admins and site visitors, potentially leading to significant security breaches.
Affected Version(s)
ElementsKit Elementor Addons 0 < 3.10.01
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.