CVE-2026-14596
DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it.
| Vendor | unknown |
| Product | dynamickit for elementor |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown dynamickit for elementor
Be the first to know when new unknown vulnerabilities affecting unknown dynamickit for elementor are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / DynamicKit for Elementor
0 < 1.0.3
References
Credits
Pedro Pinho WPScan