CVE-2026-86788 Details
Description
The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the content is viewed, including by higher-privileged users who review or publish it.
A stored cross-site scripting vulnerability has been identified in the HT Mega Addons for Elementor WordPress plugin, affecting versions prior to 3.2.6. The issue arises because the plugin does not properly validate the HTML tag names used for section headlines in various widgets and blocks. This lack of validation allows users with contributor-level access and above to inject a crafted tag name that executes arbitrary JavaScript. The injected script is executed when the content is viewed, including by users with higher privileges who review or publish the content.
Users are advised to update the HT Mega Addons for Elementor WordPress plugin to version 3.2.6 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/20cad1a6-944e-40f8-8fbc-d97cd1e5bb4b/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| HT Mega Addons | >= 3.2.0, <= 3.2.5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 17, 2026 | New CVE Received | [email protected] |
Volerion