Impact
The vulnerability arises from the DynamicKit for Elementor WordPress plugin, versions older than 1.0.3, which fails to validate the host portion of the URL embedded in password‑reset emails. An attacker can supply a malicious host when triggering a password reset, resulting in a link that contains a legitimate reset key but points to an attacker‑controlled domain. If a victim clicks the link, the attacker gains full control of the victim’s account. This flaw enables unauthenticated account takeover from anywhere over the web.
Affected Systems
WordPress sites that use the DynamicKit for Elementor plugin with a version prior to 1.0.3. The plugin is identified as Unknown:DynamicKit for Elementor.
Risk and Exploitability
With a CVSS base score of 8.8, the flaw is rated high severity. The EPSS score is below 1%, and the vulnerability is not listed in the CISA KEV catalog, indicating a low overall exploitation probability. Nonetheless, the flaw is highly severe because it permits an attacker to bypass authentication entirely by manipulating a legitimate password‑reset process. The attack vector is remote: an attacker simply triggers a password reset and modifies the host part of the reset URL sent in the email, and the inclusion of a valid reset key immediately legitimizes the attacker’s control of the account.
OpenCVE Enrichment