Description
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.
Published: 2026-07-31
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ElementsKit Lite WordPress plugin before version 3.10.01 stores megamenu menu‑item settings without sanitizing or escaping them. Because the plugin does not enforce the unfiltered_html capability when saving these settings, an administrator with subsite privileges on a multisite network can insert unsanitized JavaScript. Once the payload is stored it is rendered unchanged on the front end, resulting in a stored Cross‑Site Scripting vulnerability that can compromise the browser context of all users, including network Super Administrators, leading to session hijacking, data theft, or defacement.

Affected Systems

WordPress sites that use the ElementsKit Lite plugin (Elementor Addons) and have a version earlier than 3.10.01 in a multisite configuration are impacted. All sites in the network that employ the plugin in this state are susceptible to the flaw.

Risk and Exploitability

The CVSS score of 3.5 and an EPSS score of <1% indicate a low base severity and low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless the attack vector is clear: any subsite Administrator can inject malicious code into a megamenu configuration without needing the unfiltered_html capability, and the stored payload will run on every page load for any visitor, including network Super Administrators. The potential impact on confidentiality, integrity, and availability is significant because the attacker can hijack sessions, exfiltrate data, or redirect users to phishing sites.

Generated by OpenCVE AI on August 3, 2026 at 10:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade ElementsKit Lite to version 3.10.01 or later
  • Temporarily disable the megamenu feature or remove the plugin until the upgrade is applied
  • Restrict or remove subsite Administrator privileges on the multisite network

Generated by OpenCVE AI on August 3, 2026 at 10:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.
Title ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-31T17:45:29.200Z

Reserved: 2026-06-26T07:33:52.723Z

Link: CVE-2026-13393

cve-icon Vulnrichment

Updated: 2026-07-31T17:44:16.061Z

cve-icon NVD

Status : Received

Published: 2026-07-31T07:16:24.277

Modified: 2026-07-31T18:17:10.500

Link: CVE-2026-13393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')