Back to CVE List

CVE-2026-13392

Vulnerability Description

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution beyond the privileges the network grants them.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
ElementsKit Elementor Addons

External References

Discussion (0)

Add Comment

No comments yet. Be the first!