Unrated severityNVD Advisory· Published Sep 17, 2026
CVE-2026-86788
CVE-2026-86788
Description
The HT Mega Addons for Elementor WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the content is viewed, including by higher-privileged users who review or publish it.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <3.2.6
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.