WordPress security by component
DynamicKit for Elementor
Plugin description
DynamicKit for Elementor is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
dynamickit-for-elementorLatest vulnerability
CVE-2026-14596: DynamicKit can email valid password-reset keys to attacker-controlled hosts
DynamicKit for Elementor before 1.0.3 uses a visitor-supplied URL as the base of the password-reset link it emails without validating the host. An unauthenticated attacker can target a user and cause WordPress to send a legitimate-looking reset email whose link points to the attacker's host and contains a valid reset key. If the victim clicks, the attacker-controlled server receives the key and can use it to take over the account. The record does not disclose the request endpoint, URL parameter or link-building function.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-14596
DynamicKit can email valid password-reset keys to attacker-controlled hosts
DynamicKit for Elementor before 1.0.3 uses a visitor-supplied URL as the base of the password-reset link it emails without validating the host. An unauthenticated attacker can target a user and cause WordPress to send a legitimate-looking reset email whose link points to the attacker's host and contains a valid reset key. If the victim clicks, the attacker-controlled server receives the key and can use it to take over the account. The record does not disclose the request endpoint, URL parameter or link-building function.
|
1.0.3 |
CVEPending
NVDPending
|