CVE-2026-13392
Vulnerability Description
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution beyond the privileges the network grants them.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
ElementsKit Elementor Addons
Discussion (0)
Add Comment
No comments yet. Be the first!