What is CVE-2026-13344?
CVE-2026-13344: In the Essential Addons for Elementor WordPress plugin before version 6.6.10, the HTML tag name for the Pricing Table widget title is not validated before being output. This allows users with Contributor-level access and above to inject arbitrary JavaScript that will be executed when the page is loaded, resulting in a Stored Cross-Site Scripting (XSS) vulnerability. Affected sites should immediately update to version 6.6.10 or later.
Azərbaycanca: CVE-2026-13344: 'Essential Addons for Elementor' WordPress plagininin 6.6.10-dan əvvəlki versiyalarında Qiymət Cədvəli (Pricing Table) vidjetinin başlığındakı HTML etiket adı düzgün yoxlanılmır. Bu, Contributor və daha yüksək səviyyəli istifadəçilərə Stored XSS hücumu vasitəsilə səhifə baxışı zamanı icra olunan JavaScript kodu yerləşdirməyə imkan verir. Plagindən istifadə edən sayt sahibləri dərhal 6.6.10 və ya daha yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which component of the 'Essential Addons for Elementor' plugin does the CVE-2026-13344 vulnerability exist?
The CVE-2026-13344 vulnerability exists due to the improper validation of the HTML tag name in the Pricing Table widget title of the 'Essential Addons for Elementor' plugin.
To which version must the 'Essential Addons for Elementor' plugin be updated to protect against CVE-2026-13344?
To protect against CVE-2026-13344, the 'Essential Addons for Elementor' plugin must be updated to version 6.6.10 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.