CVE · Medium

CVE-2026-4362 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.9.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-4362 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.9.0 Missing Authorization Medium 6.5 < 3.9.0 3.9.0 2026-05-04

CVE-2026-4362

A flaw in the ElementsKit Elementor Addons plugin for WordPress allows unauthenticated attackers to modify data without authorization. This vulnerability arises from the absence of capability checks on the Live_Action::reset() function, which is triggered when certain conditions are met during the WordPress initialization process. As a result, malicious visitors can create URLs that exploit this weakness and overwrite custom widget designs, text, and settings with default values.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.