CVE-2026-13344

Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.


We have discovered 261,484 live websites that are affected by CVE-2026-13344.

Run a Free Instant Scan




Affected Software

Product  Essential Addons for Elementor
Category Wordpress Plugins
Vulnerable Domains261,484 live websites (99% of Essential Addons for Elementor install base)
Vulnerable Versions
  • from 0 through 6.6.10
Vulnerable Versions Count165 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Revanth Hari Narayana Matte (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-13344
United States79,351 websites



Germany24,381 websites
France15,207 websites
Brazil11,756 websites
GB11,296 websites
Spain8,721 websites
Italy8,202 websites
India8,059 websites
Netherlands6,744 websites
Poland5,713 websites

Website Distribution by TLD

Number of websites using CVE-2026-13344
.com109,393 websites
.org15,907 websites
.de13,934 websites
.com.br10,616 websites
.fr7,014 websites
.co.uk6,191 websites
.nl5,903 websites
.it5,890 websites
.net4,835 websites
.com.au4,499 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-13344

Top websites that are affected by CVE-2026-13344. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.net United States*,***
******.com United States*,***
******.com France*,***
******.com United States*,***
********.org United States*,***
********.com United States*,***
****************.nl United States*,***
*********.com United States*,***
******************.de Germany**,***
*******.co Serbia**,***
See full domain list

FAQ

CVE-2026-13344 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Essential Addons for Elementor
A total of 261,484 websites have been identified as vulnerable to CVE-2026-13344, based on global website indexing conducted by WebTechSurvey.
The Essential Addons for Elementor is affected by the CVE-2026-13344 vulnerability.
Essential Addons for Elementor versions up to 6.6.10 are vulnerable to CVE-2026-13344.
CVE-2026-13344 is resolved in version 6.6.10 of Essential Addons for Elementor.