Sceawere

Vulnerability Detail

CVE-2026-11895UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

HT Mega Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
devitemsllc
Product
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Data Table 'display_options' Setting in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-09-30T08:16:32.667Z",
  "pubdate": "2026-09-30T08:16:32.667Z",
  "executiveSummary": "The HT Mega Addons for Elementor – Elementor Widgets & Template Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability, present in all versions up to and including 3.1.1, originates from insufficient input sanitization and output escaping within the Data Table 'display_options' setting.\nThe flaw allows authenticated attackers with contributor-level privileges or higher to inject malicious JavaScript into web pages.\nWhen a victim, such as an administrator, accesses an affected page containing the injected payload, the script executes within the context of their browser session.\nThis poses significant security risks, including the potential for unauthorized actions, session hijacking, or the theft of sensitive session cookies.\nThe vulnerability effectively leverages the trust between the site and its authenticated users to compromise administrative sessions.\nThe requirement for authenticated access restricts the attack vector, but the elevated privilege level of a contributor is sufficient to facilitate exploitation.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the HT Mega Addons plugin to properly sanitize user-supplied input or escape output when processing the 'display_options' setting within its Data Table widget.\nIn WordPress plugin development, input validation must occur before data is stored in the database, and output escaping must occur immediately before data is rendered in the browser.\nThe application accepts arbitrary user input through the 'display_options' field during the configuration of the Data Table widget. Because the plugin does not implement adequate input validation filters (such as WordPress 'sanitize_text_field' or 'wp_kses_post') or output escaping functions (such as 'esc_html' or 'esc_js'), malicious payloads can be successfully stored.\nAn attacker with at least contributor-level privileges can navigate to the widget settings and inject an arbitrary script tag, for example, <script>alert('XSS')</script>, into the vulnerable 'display_options' parameter.\nOnce the settings are saved, the injected script is persisted in the WordPress database.\nThe attack flow continues when an unsuspecting victim, such as a site administrator, loads a page containing the compromised Data Table widget.\nThe server-side code retrieves the tainted 'display_options' data from the database and renders it directly into the HTML response without any sanitization or escaping mechanisms.\nConsequently, the victim's browser interprets the stored data as valid HTML and executes the malicious script embedded by the attacker.\nBecause this script runs within the context of the victim's session, the attacker can perform unauthorized operations on behalf of the victim. This includes modifying site configurations, deleting content, or creating new administrative accounts if the victim possesses such permissions.\nFurthermore, this vulnerability facilitates the exfiltration of sensitive information, such as session cookies or CSRF tokens, which the attacker can use to impersonate the victim.\nThe exposure is limited to authenticated users with access to the widget configuration interface, but within that scope, the lack of input/output handling creates a persistent threat vector across the site."
}
CVE-2026-11895: HT Mega Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.4) | Sceawere