PatchSiren cyber security CVE debrief
CVE-2026-13392 ElementsKit CVE debrief
The ElementsKit Elementor Addons WordPress plugin before version 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the plugin subsequently executes, allowing arbitrary PHP code to run on the server. This vulnerability can be exploited by a non-super subsite Administrator on a multisite network, allowing them to achieve host-level code execution beyond the privileges the network grants them. The vulnerability has a CVSS score of 7.2 and a severity of HIGH. Administrators of WordPress installations with the ElementsKit Elementor Addons plugin should be aware of this vulnerability and take steps to mitigate it. They should prioritize updating to version 3.10.01 or later and restrict administrative capabilities to trusted users. Additionally, they should monitor server logs for suspicious activity and review compensating controls for exposed systems while remediation is scheduled and verified.
- Vendor
- ElementsKit
- Product
- ElementsKit Elementor Addons
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-07-31
Who should care
Administrators of WordPress installations with the ElementsKit Elementor Addons plugin, especially those with multisite networks, should be aware of this vulnerability and take steps to mitigate it. They should prioritize updating to version 3.10.01 or later and restrict administrative capabilities to trusted users. Additionally, they should monitor server logs for suspicious activity and review compensating controls for exposed systems while remediation is scheduled and verified. Security teams and vulnerability management teams should also be aware of this vulnerability and track exceptions and retest remediated assets.
Technical summary
The ElementsKit Elementor Addons WordPress plugin before version 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the plugin subsequently executes, allowing arbitrary PHP code to run on the server. This vulnerability can be exploited by a non-super subsite Administrator on a multisite network, allowing them to achieve host-level code execution beyond the privileges the network grants them. The vulnerability has a CVSS score of 7.2 and a severity of HIGH.
Defensive priority
Administrators of WordPress installations with the ElementsKit Elementor Addons plugin should prioritize updating to version 3.10.01 or later to mitigate this vulnerability.
Recommended defensive actions
- Update the ElementsKit Elementor Addons plugin to version 3.10.01 or later
- Restrict administrative capabilities to trusted users
- Monitor server logs for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record indicates that the ElementsKit Elementor Addons WordPress plugin before version 3.10.01 allows arbitrary PHP code execution on the server due to improper handling of custom-widget definitions. The vulnerability is rated with a CVSS score of 7.2 and a severity of HIGH. Administrators should verify the plugin version and update to 3.10.01 or later. They should also monitor server logs for suspicious activity and restrict administrative capabilities to trusted users. Evidence is limited to public CVE and NVD details.
Official resources
-
CVE-2026-13392 CVE record
CVE.org
-
CVE-2026-13392 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T07:16:24.163Z and has not been modified since then.