What is CVE-2026-13393?
This is a vulnerability in the ElementsKit Elementor Addons plugin for WordPress. Versions before 3.10.01 do not sanitize or escape certain megamenu settings before storing and outputting them, allowing users with administrative capabilities to inject malicious code. The plugin should be updated to the latest version immediately.
Azərbaycanca: Bu, WordPress üçün ElementsKit Elementor Addons plaginində aşkar edilmiş zəiflikdir. Plagin 3.10.01 versiyasından əvvəlki versiyalarda megamenu parametrlərini sanitizasiya etmir və saxlamadan əvvəl yoxlamır, bu da admin səlahiyyətləri olan istifadəçilərə zərərli kod yerləşdirməyə imkan verir. Plagin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the ElementsKit Elementor Addons plugin are affected by CVE-2026-13393?
This vulnerability affects all versions of the plugin prior to 3.10.01.
What level of permissions does an attacker need to exploit CVE-2026-13393?
To exploit this vulnerability, an attacker needs access to a user account with administrative capabilities.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.