{"api_version":"1","generated_at":"2026-09-17T06:47:16+00:00","cve":"CVE-2026-86788","urls":{"html":"https://cve.report/CVE-2026-86788","api":"https://cve.report/api/cve/CVE-2026-86788.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-86788","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-86788"},"summary":{"title":"HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag","description":"The HT Mega Addons for Elementor  WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the content is viewed, including by higher-privileged users who review or publish it.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-17 06:16:51","updated_at":"2026-09-17 06:16:51"},"problem_types":["CWE-79 Cross-Site Scripting (XSS)"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/20cad1a6-944e-40f8-8fbc-d97cd1e5bb4b/","name":"https://wpscan.com/vulnerability/20cad1a6-944e-40f8-8fbc-d97cd1e5bb4b/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-86788","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86788","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"HT Mega Addons for Elementor","version":"affected 3.2.0 3.2.6 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Revanth Hari Narayana Matte","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"HT Mega Addons for Elementor","vendor":"Unknown","versions":[{"lessThan":"3.2.6","status":"affected","version":"3.2.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Revanth Hari Narayana Matte"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The HT Mega Addons for Elementor  WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the content is viewed, including by higher-privileged users who review or publish it."}],"problemTypes":[{"descriptions":[{"description":"CWE-79 Cross-Site Scripting (XSS)","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-17T06:00:10.546Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/20cad1a6-944e-40f8-8fbc-d97cd1e5bb4b/"}],"source":{"discovery":"EXTERNAL"},"title":"HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-86788","datePublished":"2026-09-17T06:00:10.546Z","dateReserved":"2026-09-08T11:51:49.821Z","dateUpdated":"2026-09-17T06:00:10.546Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 06:16:51","lastModifiedDate":"2026-09-17 06:16:51","problem_types":["CWE-79 Cross-Site Scripting (XSS)"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"86788","Ordinal":"1","Title":"HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Head","CVE":"CVE-2026-86788","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"86788","Ordinal":"1","NoteData":"The HT Mega Addons for Elementor  WordPress plugin before 3.2.6 does not restrict the HTML tag name used to render the section headline in several of its widgets and blocks to a safe allowlist, allowing users with contributor-level access and above to store a crafted tag name that executes arbitrary JavaScript when the content is viewed, including by higher-privileged users who review or publish it.","Type":"Description","Title":"HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Head"}]}}}