S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Web Vulnerabilities·Updated Sep 7, 2026

CVE-2026-23693 Scanner

CVE-2026-23693 Scanner - Unauthorized Admin Access vulnerability in ElementsKit Lite

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-23693
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open proxy to Mailchimp, potentially triggering unauthorized API calls, manipulating subscription data, exhausting API quotas, or causing resource consumption on the affected WordPress site.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementorby Roxnor
AFFECTED< 3.7.9SAFE ✓≥ 3.7.9
Updated Sep 7, 2026View on NVD →
Detail

The ElementsKit Lite plugin is an add-on for the WordPress content management system. It allows users to enhance their Elementor page building capabilities with additional widgets and features. This plugin is widely used by web developers and site administrators to create advanced layouts and functionalities without coding knowledge. The primary audience for this plugin includes WordPress site designers, digital marketers, and small to medium-sized businesses looking for customizable design options. The plugin is popular due to its ease of integration with WordPress and compatibility with various themes and other plugins. It supports a range of customizations and is continuously updated to incorporate new elements and improve performance.

The unauthorized admin access vulnerability lies in the unrestricted REST route registered by the ElementsKit Lite plugin. This route allows unauthenticated attackers to issue requests to the Mailchimp API through the hosting WordPress site. Without proper authentication checks, attackers can abuse the website as an open proxy, leading to a range of malicious activities. The vulnerability is critical as it opens opportunities for abusing Mailchimp integration, and possibly for further exploitation. It compromises the security integrity of WordPress sites using any version of the plugin before 3.7.9. Corrective measures are necessary to prevent malicious exploitation of the feature.

Technical details of this vulnerability reveal that the vulnerable endpoint is '/wp-json/elementskit/v1/widget/mailchimp/subscribe'. The parameter potentially exploited is the Mailchimp API credentials, which are accepted without verification. Attackers can invoke this endpoint with crafted requests, leading the website to interact with Mailchimp's servers on behalf of the attacker. It bypasses control mechanisms that would normally safeguard such operations, allowing unauthorized access. Exploitation does not require authentication on the WordPress site, which makes it particularly dangerous for unprotected sites. The vulnerability could lead to the abuse of Mailchimp's resources and manipulation of subscription data.

If exploited, this vulnerability may result in significant consequences including unauthorized use of Mailchimp API quotas and resources. Attackers could manipulate subscription lists and tamper with data sent to Mailchimp, potentially leading to mass spam or phishing campaigns. The hosting site could face severe resource exhaustion or rate-limit issues from Mailchimp due to abuse by the attacker. Unauthorized access can also degrade trust with site users and linked services. Ultimately, the website's integration capabilities are hijacked, posing a risk to its data integrity and operational reliability.

REFERENCES

Solution Advice
  • Update to the latest version of the ElementsKit Lite plugin, 3.7.9 or later, where authentication on vulnerable endpoints is enforced.
  • Review and audit your website plugins for any unauthorized or unusual API requests.
  • Implement and thoroughly test access controls to ensure only authenticated users can invoke sensitive operations in all integrated applications.
  • Regularly check for plugin updates and revisions to stay protected against future vulnerabilities.
  • Utilize a web application firewall (WAF) to help block malicious traffic and unauthorized attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-23693 Scanner - Unauthorized Admin Access vulnerability in ElementsKit Lite | S4E