Description
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution beyond the privileges the network grants them.
Published: 2026-07-31
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ElementsKit Elementor Addons WordPress plugin allows a user with administrative access to define a custom widget that is written verbatim into a PHP file on the server. This file is subsequently executed by the plugin, allowing the attacker to run arbitrary PHP code. The result is a full compromise of the web server, providing an attacker with host‑level code execution beyond the privileges normally granted to a subsite administrator on a multisite network.

Affected Systems

The vulnerability is present in all versions of ElementsKit Elementor Addons prior to 3.10.01, especially on multisite WordPress installations. Users who own a subsite with administrative rights can exploit the flaw, while super‑administrators are not affected by the attack vector described.

Risk and Exploitability

With an EPSS score of 0.0037, the exploit probability is very low but non‑zero. The flaw delivers remote code execution, which is the highest impact level. The absence of a KEV listing does not diminish the critical nature of the vulnerability. The attack requires the ability to create or edit a custom widget within the plugin, a task typically limited to site administrators. Once achieved, the attacker can run arbitrary PHP, potentially exfiltrating data, installing backdoors, or elevating privileges on the host.

Generated by OpenCVE AI on August 3, 2026 at 10:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ElementsKit Elementor Addons to version 3.10.01 or later
  • Restrict subsite administrator access to the Custom Widget Builder feature—or disable that feature in plugin settings—until the plugin is upgraded
  • Scan the multisite installation for PHP files created by custom widgets and remove or revert any unauthorized code

Generated by OpenCVE AI on August 3, 2026 at 10:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution beyond the privileges the network grants them.
Title ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-31T16:49:52.762Z

Reserved: 2026-06-26T07:33:48.034Z

Link: CVE-2026-13392

cve-icon Vulnrichment

Updated: 2026-07-31T16:48:58.553Z

cve-icon NVD

Status : Received

Published: 2026-07-31T07:16:24.163

Modified: 2026-07-31T17:16:32.190

Link: CVE-2026-13392

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:15:03Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')