WordPress Plugin Vulnerabilities

ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)

Description

The plugin does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with administrative capabilities to store malicious JavaScript; on a multisite network this lets a non-super subsite Administrator, who is denied unfiltered_html, plant a stored Cross-Site Scripting payload that executes in the sessions of the network Super Admin and site visitors.

Proof of Concept

Affects Plugins

Fixed in 3.10.01

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-07-14 (about 1 month ago)
Added
2026-07-14 (about 1 month ago)
Last Updated
2026-07-14 (about 1 month ago)

Other