๐Ÿ” CVE Alert

CVE-2026-13392

UNKNOWN 0.0

ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution beyond the privileges the network grants them.

Vendor unknown
Product elementskit elementor addons
Published Jul 31, 2026
Stay Ahead of the Next One

Get instant alerts for unknown elementskit elementor addons

Be the first to know when new unknown vulnerabilities affecting unknown elementskit elementor addons are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / ElementsKit Elementor Addons
0 < 3.10.01

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/955cbef5-51c3-4d10-86d2-e2882bbb56a4/

Credits

Revanth Hari Narayana Matte WPScan