Description
Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2.
Published: 2026-02-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Broken Access Control
Action: Apply Patch
AI Analysis

Impact

This vulnerability is a missing authorization flaw (CWE-862) that allows attackers to exploit improperly configured access control levels within the News Kit Elementor Addons plugin. An attacker who can interact with the plugin’s administrative interfaces could gain unauthorized privileges, potentially reading, modifying, or deleting content and settings. The weakness stems from a failure to enforce role-based protection, making confidentiality and integrity of site data at risk for any user who can reach the plugin endpoints.

Affected Systems

The flaw affects the WordPress plugin News Kit Elementor Addons by blazethemes, versions from the earliest release through 1.4.2. Users running the plugin on WordPress sites must verify their installation version. No later versions are known to be impacted.

Risk and Exploitability

The CVSS vector scores the vulnerability at 4.3, indicating moderate risk, while the EPSS score of less than 1% suggests a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote, achievable by any authenticated or unauthenticated user who can access plugin administrative pages. Exploitation requires no special hardware or privileged network access, but it does rely on the presence of an accessible WordPress instance with the affected plugin installed.

Generated by OpenCVE AI on April 16, 2026 at 06:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the News Kit Elementor Addons plugin to any version newer than 1.4.2
  • Reconfigure user roles to ensure no user has unnecessary administrator privileges for the plugin
  • If an upgrade is not immediately possible, restrict HTTP access to plugin management URLs using a firewall or .htaccess rules
  • Implement logging and monitor plugin activity for anomalous access patterns

Generated by OpenCVE AI on April 16, 2026 at 06:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Blazethemes
Blazethemes news Kit Elementor Addons
Wordpress
Wordpress wordpress
Vendors & Products Blazethemes
Blazethemes news Kit Elementor Addons
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Thu, 19 Feb 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects News Kit Elementor Addons: from n/a through <= 1.4.2.
Title WordPress News Kit Elementor Addons plugin <= 1.4.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Blazethemes News Kit Elementor Addons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:14:56.730Z

Reserved: 2026-02-02T12:53:26.261Z

Link: CVE-2026-25416

cve-icon Vulnrichment

Updated: 2026-02-19T19:32:00.676Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T09:16:23.320

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-25416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T06:30:06Z

Weaknesses