PatchSiren cyber security CVE debrief
CVE-2026-13392 ElementsKit CVE debrief
The ElementsKit Elementor Addons WordPress plugin before version 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the plugin subsequently executes, allowing arbitrary PHP code to run on the server. This vulnerability can be exploited by a non-super subsite Administrator on a multisite network, allowing them to achieve host-level code execution beyond the privileges the network grants them. The vulnerability has a CVSS score of 7.2 and a severity of HIGH. Administrators of WordPress installations with the ElementsKit Elementor Addons plugin should be aware of this vulnerability and take steps to mitigate it. They should prioritize updating to version 3.10.01 or later and restrict administrative capabilities to trusted users. Additionally, they should monitor server logs for suspicious activity and review compensating controls for exposed systems while remediation is scheduled and verified.
- Vendor
- ElementsKit
- Product
- ElementsKit Elementor Addons
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-31
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-07-31
- Advisory updated
- 2026-08-26
Who should care
Administrators of WordPress installations with the ElementsKit Elementor Addons plugin, especially those with multisite networks, should be aware of this vulnerability and take steps to mitigate it. They should prioritize updating to version 3.10.01 or later and restrict administrative capabilities to trusted users. Additionally, they should monitor server logs for suspicious activity and review compensating controls for exposed systems while remediation is scheduled and verified. Security teams and vulnerability management teams should also be aware of this vulnerability and track exceptions and retest remediated assets.
Technical summary
The ElementsKit Elementor Addons WordPress plugin before version 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the plugin subsequently executes, allowing arbitrary PHP code to run on the server. This vulnerability can be exploited by a non-super subsite Administrator on a multisite network, allowing them to achieve host-level code execution beyond the privileges the network grants them. The vulnerability has a CVSS score of 7.2 and a severity of HIGH.
Defensive priority
Administrators of WordPress installations with the ElementsKit Elementor Addons plugin should prioritize updating to version 3.10.01 or later to mitigate this vulnerability.
Recommended defensive actions
- Update the ElementsKit Elementor Addons plugin to version 3.10.01 or later
- Restrict administrative capabilities to trusted users
- Monitor server logs for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The CVE record indicates that the ElementsKit Elementor Addons WordPress plugin before version 3.10.01 allows arbitrary PHP code execution on the server due to improper handling of custom-widget definitions. The vulnerability is rated with a CVSS score of 7.2 and a severity of HIGH. Administrators should verify the plugin version and update to 3.10.01 or later. They should also monitor server logs for suspicious activity and restrict administrative capabilities to trusted users. Evidence is limited to public CVE and NVD details.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-13392 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-13392
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-13392 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13392
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/955cbef5-51c3-4d10-86d2-e2882bbb56a4/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.