CVE-2026-2600 is a stored cross-site scripting vulnerability in the ElementsKit Elementor Addons and Templates plugin for WordPress. The issue affects the Simple Tab widget in all versions up to and including 3.7.9. It is caused by insufficient input sanitization and output escaping of user-supplied data passed via the 'ekit_tab_title' parameter. An authenticated attacker with contributor-level privileges or higher can inject arbitrary JavaScript or other malicious client-side script into page content, where it is stored and later executed in victims' browsers when they access the affected page.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small Python exploit repo for CVE-2026-2600, a stored XSS vulnerability in Wpmet ElementsKit Elementor Addons <= 3.7.9. It contains three files: a README with vulnerability details and usage examples, a primary CLI exploit script (poc.py), and an interactive menu-driven variant (console_poc.py). The exploit is not part of a larger framework. The core capability is authenticated web exploitation against WordPress. Using Contributor+ credentials, the scripts log into WordPress, obtain a REST nonce from the admin/editor context, create a draft post through the WordPress REST API, and then patch the post's _elementor_data metadata with a crafted Elementor widget tree. The malicious tree uses widgetType 'elementskit-simple-tab' and places attacker-controlled HTML/JavaScript into the ekit_tab_title field, which the vulnerable plugin renders without proper escaping. The script can then publish the post and verify that the payload appears in the page source. The repository targets a specific exploitation path: bypassing Elementor's client-side sanitization by writing directly to /wp-json/wp/v2/posts and related post endpoints. The exploit therefore depends on authenticated access and the vulnerable plugin/widget behavior, but once successful it yields persistent browser-side code execution for anyone visiting the infected page, including administrators. The README and script comments explicitly describe use cases such as cookie theft, session hijacking, phishing overlays, and persistent defacement. poc.py appears to be the main entry point for automated exploitation. It accepts target URL, username, password, optional callback URL, optional custom payload, payload type selection, SSL verification control, and publication behavior. console_poc.py provides the same attack flow in an interactive terminal UI for demonstrations or manual step-by-step operation. Overall, this is a real operational PoC exploit for authenticated stored XSS, not merely a detector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.