PatchSiren cyber security CVE debrief
CVE-2026-13393 ElementsKit CVE debrief
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors. This vulnerability has a CVSS score of 3.5 and is considered LOW severity. The CVE record was published on 2026-07-31T07:16:24.277Z and has not been modified since then.
- Vendor
- ElementsKit
- Product
- ElementsKit Elementor Addons
- CVSS
- LOW 3.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Administrators of WordPress installations with the ElementsKit Elementor Addons plugin, and users with administrative capabilities on those installations, should review and update the plugin to version 3.10.01 or later, and ensure that users with administrative capabilities are properly authenticated and authorized. Additionally, users with administrative capabilities on multisite networks should be aware of the potential for non-super subsite Administrators to plant stored Cross-Site Scripting payloads that execute in the sessions of the network Super Admin and site visitors. It is also recommended to monitor for suspicious activity on the WordPress installation and to review compensating controls for exposed systems while remediation is scheduled and verified. Affected operators, platforms, vulnerability-management, and security teams should prioritize updating the plugin and ensuring proper authentication and authorization for users with administrative capabilities. This may involve reviewing current user roles and capabilities, as well as implementing additional security measures such as monitoring for suspicious activity and reviewing compensating controls for exposed systems. Furthermore, it is essential to consider the potential impact on the overall security posture of the organization and to take steps to mitigate any potential risks associated with this vulnerability. This includes verifying that all necessary security controls are in place and that users are aware of the potential risks and are taking steps to mitigate them. By taking these steps, organizations can help to ensure that their WordPress installations are secure and that the risk of exploitation is minimized. The affected product or component is the ElementsKit Elementor Addons WordPress plugin, and the vulnerability class is a stored Cross-Site Scripting (XSS) vulnerability. The likely operational impact of this vulnerability is that an attacker could plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors, potentially allowing them to perform actions on behalf of the Super Admin or site visitors. The source-confidence limits
Technical summary
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.
Defensive priority
Administrators of WordPress installations with the ElementsKit Elementor Addons plugin should review and update the plugin to version 3.10.01 or later, and ensure that users with administrative capabilities are properly authenticated and authorized.
Recommended defensive actions
- Review and update the ElementsKit Elementor Addons plugin to version 3.10.01 or later
- Ensure that users with administrative capabilities are properly authenticated and authorized
- Monitor for suspicious activity on the WordPress installation
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end. This allows users with administrative capabilities to store malicious JavaScript. On a multisite network, a non-super subsite Administrator can plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.
Official resources
-
CVE-2026-13393 CVE record
CVE.org
-
CVE-2026-13393 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T07:16:24.277Z and has not been modified since then.