---
id: CVE-2026-86788
title: >-
  The HT Mega Addons for Elementor  WordPress plugin before 3.2.6 does not
  restrict the HTML tag name used to render the section headline in several of
  its widgets and blocks to a safe allowlist, allowing users with
  contributor-level acces…
summary: >-
  The HT Mega Addons for Elementor  WordPress plugin before 3.2.6 does not
  restrict the HTML tag name used to render the section headline in several of
  its widgets and blocks to a safe allowlist, allowing users with
  contributor-level acces…
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: HT Mega Addons for Elementor
affected:
  - ht_mega_addons_for_elementor >= 3.2.0 < 3.2.6
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86788'
references:
  - url: 'https://wpscan.com/vulnerability/20cad1a6-944e-40f8-8fbc-d97cd1e5bb4b/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00431
epssPercentile: 0.34716
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-17T12:13:06.793353Z'
ingestedAt: '2026-09-17T06:12:17.975Z'
---

## Overview

The HT Mega Addons for Elementor  WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the content is viewed, including by higher-privileged users who review or publish it.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
