SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-13344

MEDIUM · CVSS 4.8 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The Essential Addons for Elementor WordPress plugin prior to version 6.6.10 is vulnerable to Stored Cross-Site Scripting (XSS) due to improper validation of HTML tag names in the Pricing Table widget title. This flaw allows users with Contributor-level access or higher to inject malicious JavaScript, which can execute in the context of any user viewing the page, including administrators. WordPress site administrators and developers using this plugin should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-13344
Severity
MEDIUM
CVSS
4.8
EPSS
0.17%
WordPress Java

Original NVD Description

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.