๐Ÿ” CVE Alert

CVE-2026-14596

UNKNOWN 0.0

DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it.

Vendor unknown
Product dynamickit for elementor
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for unknown dynamickit for elementor

Be the first to know when new unknown vulnerabilities affecting unknown dynamickit for elementor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / DynamicKit for Elementor
0 < 1.0.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/a23eb55c-f5b1-4dcb-8d53-6e71d80e050a/

Credits

Pedro Pinho WPScan