PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-13393 ElementsKit CVE debrief

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors. This vulnerability has a CVSS score of 3.5 and is considered LOW severity. The CVE record was published on 2026-07-31T07:16:24.277Z and has not been modified since then.

Vendor
ElementsKit
Product
ElementsKit Elementor Addons
CVSS
LOW 3.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-31
Original CVE updated
2026-07-31
Advisory published
2026-07-31
Advisory updated
2026-07-31

Who should care

Administrators of WordPress installations with the ElementsKit Elementor Addons plugin, and users with administrative capabilities on those installations, should review and update the plugin to version 3.10.01 or later, and ensure that users with administrative capabilities are properly authenticated and authorized. Additionally, users with administrative capabilities on multisite networks should be aware of the potential for non-super subsite Administrators to plant stored Cross-Site Scripting payloads that execute in the sessions of the network Super Admin and site visitors. It is also recommended to monitor for suspicious activity on the WordPress installation and to review compensating controls for exposed systems while remediation is scheduled and verified. Affected operators, platforms, vulnerability-management, and security teams should prioritize updating the plugin and ensuring proper authentication and authorization for users with administrative capabilities. This may involve reviewing current user roles and capabilities, as well as implementing additional security measures such as monitoring for suspicious activity and reviewing compensating controls for exposed systems. Furthermore, it is essential to consider the potential impact on the overall security posture of the organization and to take steps to mitigate any potential risks associated with this vulnerability. This includes verifying that all necessary security controls are in place and that users are aware of the potential risks and are taking steps to mitigate them. By taking these steps, organizations can help to ensure that their WordPress installations are secure and that the risk of exploitation is minimized. The affected product or component is the ElementsKit Elementor Addons WordPress plugin, and the vulnerability class is a stored Cross-Site Scripting (XSS) vulnerability. The likely operational impact of this vulnerability is that an attacker could plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors, potentially allowing them to perform actions on behalf of the Super Admin or site visitors. The source-confidence limits

Technical summary

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.

Defensive priority

Administrators of WordPress installations with the ElementsKit Elementor Addons plugin should review and update the plugin to version 3.10.01 or later, and ensure that users with administrative capabilities are properly authenticated and authorized.

Recommended defensive actions

  • Review and update the ElementsKit Elementor Addons plugin to version 3.10.01 or later
  • Ensure that users with administrative capabilities are properly authenticated and authorized
  • Monitor for suspicious activity on the WordPress installation
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end. This allows users with administrative capabilities to store malicious JavaScript. On a multisite network, a non-super subsite Administrator can plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T07:16:24.277Z and has not been modified since then.