Executive brief
HT Mega Addons for Elementor is a WordPress plugin that provides additional widgets and blocks for the Elementor page builder. The plugin fails to validate HTML tag names in the section headline feature, allowing contributors and higher-privileged users to inject malicious code that executes as JavaScript in the browser when content is viewed by other users, potentially compromising accounts or stealing sensitive data.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw in the section headline rendering functionality of multiple widgets and blocks (CWE-79). The plugin does not restrict the HTML tag name to a safe allowlist, allowing authenticated users with contributor-level access and above to craft and store arbitrary tag names that execute JavaScript when the content is viewed. The attack is stored server-side, meaning it affects all users who view the compromised content, including site administrators and editors. No special preconditions beyond contributor access are required to exploit this vulnerability. The vulnerability affects versions 3.2.0 through 3.2.5, and a fix is available in version 3.2.6.
Affected products
- HT Mega Addons for Elementor before 3.2.6
Timeline
- 2026-09-15: disclosed
- 2026-09-17: advisory
- 2026-09-15: patched: Fixed in version 3.2.6