The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.
We have discovered 261,484 live websites that are affected by CVE-2026-13344.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 261,484 live websites (99% of Essential Addons for Elementor install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 165 versions ( 97% of all versions) |
| 79,351 websites | |
| 24,381 websites | |
| 15,207 websites | |
| 11,756 websites | |
| 11,296 websites | |
| 8,721 websites | |
| 8,202 websites | |
| 8,059 websites | |
| 6,744 websites | |
| 5,713 websites |
| .com | 109,393 websites |
| .org | 15,907 websites |
| .de | 13,934 websites |
| .com.br | 10,616 websites |
| .fr | 7,014 websites |
| .co.uk | 6,191 websites |
| .nl | 5,903 websites |
| .it | 5,890 websites |
| .net | 4,835 websites |
| .com.au | 4,499 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.net | *,*** | ||
| ******.com | *,*** | ||
| ******.com | *,*** | ||
| ******.com | *,*** | ||
| ********.org | *,*** | ||
| ********.com | *,*** | ||
| ****************.nl | *,*** | ||
| *********.com | *,*** | ||
| ******************.de | **,*** | ||
| *******.co | **,*** |
FAQ