Threats Tagged 'cve-2026-13393'
View all threats tagged with 'cve-2026-13393'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-13393'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-13393: CWE-79 Cross-Site Scripting (XSS) in ElementsKit Elementor AddonsCVE-2026-13393 0 The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors. Join the discussion | CVE Database V5 | 07/31/2026, 06:00:11 UTC Added: 07/31/2026, 06:37:40 UTC |
Showing 1 to 1 of 1 result