The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.
We have discovered 166,444 live websites that are affected by CVE-2026-13393.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 166,444 live websites (100% of ElementsKit install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 136 versions ( 100% of all versions) |
| 44,347 websites | |
| 13,050 websites | |
| 10,201 websites | |
| 10,177 websites | |
| 7,710 websites | |
| 7,567 websites | |
| 5,605 websites | |
| 5,297 websites | |
| 5,119 websites | |
| 4,423 websites |
| .com | 73,730 websites |
| .com.br | 9,346 websites |
| .org | 7,091 websites |
| .de | 5,778 websites |
| .co.uk | 3,836 websites |
| .it | 3,683 websites |
| .net | 3,495 websites |
| .pl | 3,347 websites |
| .fr | 3,306 websites |
| .nl | 2,872 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | *,*** | ||
| ****************.com | **,*** | ||
| ********.***.br | **,*** | ||
| **********.com | **,*** | ||
| ******.com | **,*** | ||
| ******.com | **,*** | ||
| *****.io | **,*** | ||
| *****************.com | **,*** | ||
| ******************.com | **,*** | ||
| ********.com | **,*** |
FAQ