← WordPress Vulnerabilities
WordPress security by component

DynamicKit for Elementor

DynamicKit for Elementor is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: dynamickit-for-elementor

CVE-2026-14596: DynamicKit can email valid password-reset keys to attacker-controlled hosts

DynamicKit for Elementor before 1.0.3 uses a visitor-supplied URL as the base of the password-reset link it emails without validating the host. An unauthenticated attacker can target a user and cause WordPress to send a legitimate-looking reset email whose link points to the attacker's host and contains a valid reset key. If the victim clicks, the attacker-controlled server receives the key and can use it to take over the account. The record does not disclose the request endpoint, URL parameter or link-building function.

PublishedAug 01, 2026
Known safe version1.0.3
Safe version
Aug 01, 2026 CVE-2026-14596
DynamicKit can email valid password-reset keys to attacker-controlled hosts
DynamicKit for Elementor before 1.0.3 uses a visitor-supplied URL as the base of the password-reset link it emails without validating the host. An unauthenticated attacker can target a user and cause WordPress to send a legitimate-looking reset email whose link points to the attacker's host and contains a valid reset key. If the victim clicks, the attacker-controlled server receives the key and can use it to take over the account. The record does not disclose the request endpoint, URL parameter or link-building function.
1.0.3
CVEPending
NVDPending