CVE-2026-23693

CRITICAL

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/...

Affects 0 products across 7 vendors.

BCS6.83
CVSS 3.110.0
CVSS v49.3
EPSS0.4%
Percentile31th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-306: Missing Authentication for Critical Function

Software does not perform any authentication for functionality that requires a verified identity.

Related Attack Patterns (CAPEC)
CAPEC-12 Choosing Message Identifier
via CWE-306
CAPEC-36 Using Unpublished Interfaces or Functionality
via CWE-306
CAPEC-62 Cross Site Request Forgery
via CWE-306
CAPEC-166 Force the System to Reset Values
via CWE-306
CAPEC-216 Communication Channel Manipulation
via CWE-306

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

The ElementsKit Elementor Addons plugin for WordPress versions prior to 3.7.9 exposes an unauthenticated REST endpoint that accepts client-supplied Mailchimp API credentials and insufficiently validates parameters, posing a high risk of unauthorized access and data manipulation.

BSID: BS-2026-GLOBAL-071997-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-23693?
The ElementsKit Elementor Addons plugin for WordPress versions prior to 3.7.9 exposes an unauthenticated REST endpoint that accepts client-supplied Mailchimp API credentials and insufficiently validates parameters, posing a high risk of unauthorized access and data manipulation.
What is the CVSS score for CVE-2026-23693?
CVE-2026-23693 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H. EPSS: 0.4%.
Is CVE-2026-23693 actively exploited?
No confirmed active exploitation of CVE-2026-23693 as of 2026-05-30.
How do I remediate CVE-2026-23693?
Priority: IMMEDIATE.
What systems are affected by CVE-2026-23693?
CVE-2026-23693 affects: Abuse, Client, Elementor, Lite, Mailchimp, Plugin, Wordpress.
Vulnerability Details
CVE IDCVE-2026-23693
BSIDBS-2026-GLOBAL-071997-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
Published2026-02-23
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open proxy to Mailchimp, potentially triggering unauthorized API calls, manipulating subscription data, exhausting API quotas, or causing resource consumption on the affected WordPress site.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit the unauthenticated REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe to send malicious requests with arbitrary Mailchimp API credentials and parameters, potentially leading to unauthorized access to Mailchimp data and manipulation of the data.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Abuse —
Client —
Elementor —
Lite —
Mailchimp —
Plugin —
Wordpress —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 162 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashbd00ec931db007f162ac438e1f35e2542d040c8fae4e982b01d6e1a9a85c7e137a6144a3c05c50a67ce92dab0da478b9d7c0f7fb01750086e2ebb82b66863368
Related CVEs affecting Abuse
CVE-2024-28189 10.0 Judge0 is an open-source online code execution system. The application uses t... CVE-1999-0512 10.0 A mail server is explicitly configured to allow SMTP mail relay, which allows... CVE-2025-4378 10.0 Cleartext Transmission of Sensitive Information, Use of Hard-coded Credential... CVE-2026-40089 9.9 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. Th... CVE-2026-27389 9.8 Authentication Bypass Using an Alternate Path or Channel vulnerability in des...
View all Abuse CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →