CVE-2026-13344: Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag
The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Table widget title before outputting it, allowing users with Contributor-level access and above to inject JavaScript that will be executed (Stored Cross-Site Scripting) when the page is viewed, including in the session of an administrator previewing or visiting the post.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13344?
The severity of CVE-2026-13344 is medium with a CVSS score of 4.8.
How do I fix CVE-2026-13344?
To fix CVE-2026-13344, update the Essential Addons for Elementor plugin to version 6.6.10 or later.
What type of vulnerability is CVE-2026-13344?
CVE-2026-13344 is a stored cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2026-13344?
Users with Contributor-level access and above can be affected by CVE-2026-13344.
What is the impact of CVE-2026-13344?
The impact of CVE-2026-13344 is the potential execution of injected JavaScript code on the affected page.