CVE-2026-13392
Received Received - Intake

Arbitrary PHP Code Execution in ElementsKit Elementor Addons

Vulnerability report for CVE-2026-13392, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: WPScan

Description

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution beyond the privileges the network grants them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpmet elementskit_elementor_addons to 3.10.01 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The ElementsKit Elementor Addons WordPress plugin before version 3.10.01 has a flaw where custom-widget definitions saved by administrators are written directly into a PHP file without proper sanitization. This allows arbitrary PHP code to be executed on the server when the plugin runs the file. In multisite setups, non-super subsite administrators can exploit this to gain host-level code execution beyond their granted permissions.

Detection Guidance

Check if the ElementsKit Elementor Addons plugin version is below 3.10.01. Look for unauthorized PHP files in the plugin's generated directories or suspicious code in custom-widget definitions.

Impact Analysis

This vulnerability allows attackers with administrative access to execute arbitrary PHP code on the server. In a multisite WordPress environment, non-super subsite administrators can bypass restrictions and gain elevated privileges, potentially compromising the entire server. Attackers could install malware, steal data, or take control of the website.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating compliance requirements under GDPR and HIPAA. GDPR mandates strict data protection and breach notification, while HIPAA requires safeguarding protected health information. Exploitation may result in regulatory penalties, legal liabilities, and reputational damage.

Mitigation Strategies

Update the ElementsKit Elementor Addons plugin to version 3.10.01 or later immediately. Remove any unauthorized PHP files or suspicious code from custom-widget definitions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13392. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart