CVE-2026-23693
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/...
Affects 0 products across 7 vendors.
Software does not perform any authentication for functionality that requires a verified identity.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
The ElementsKit Elementor Addons plugin for WordPress versions prior to 3.7.9 exposes an unauthenticated REST endpoint that accepts client-supplied Mailchimp API credentials and insufficiently validates parameters, posing a high risk of unauthorized access and data manipulation.
BSID: BS-2026-GLOBAL-071997-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2026-23693?
What is the CVSS score for CVE-2026-23693?
Is CVE-2026-23693 actively exploited?
How do I remediate CVE-2026-23693?
What systems are affected by CVE-2026-23693?
| CVE ID | CVE-2026-23693 |
|---|---|
| BSID | BS-2026-GLOBAL-071997-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H |
| Published | 2026-02-23 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open proxy to Mailchimp, potentially triggering unauthorized API calls, manipulating subscription data, exhausting API quotas, or causing resource consumption on the affected WordPress site.
Source: NIST NVD / MITRE CVE Database
An attacker can exploit the unauthenticated REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe to send malicious requests with arbitrary Mailchimp API credentials and parameters, potentially leading to unauthorized access to Mailchimp data and manipulation of the data.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Abuse | — | — |
| Client | — | — |
| Elementor | — | — |
| Lite | — | — |
| Mailchimp | — | — |
| Plugin | — | — |
| Wordpress | — | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | bd00ec931db007f162ac438e1f35e2542d040c8fae4e982b01d6e1a9a85c7e137a6144a3c05c50a67ce92dab0da478b9d7c0f7fb01750086e2ebb82b66863368 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →