CVE-2026-14596
Received Received - Intake

DynamicKit for Elementor Password Reset Host Validation Bypass

Vulnerability report for CVE-2026-14596, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
dynamickit dynamickit_for_elementor to 1.0.3 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the DynamicKit for Elementor WordPress plugin before version 1.0.3. It fails to validate the host of a user-supplied URL used as the base for password-reset links. Attackers can exploit this by sending a victim a legitimate-looking reset email with a link pointing to an attacker-controlled host while carrying a valid reset key. When the victim clicks the link, it leads to account takeover.

Detection Guidance

To detect this vulnerability, check if the DynamicKit for Elementor plugin is installed and verify its version. If it is below 1.0.3, it is vulnerable. Inspect WordPress email templates for password reset links to see if they use user-supplied URLs without host validation.

Impact Analysis

If you use the affected DynamicKit for Elementor plugin, an attacker could trick you into clicking a malicious password-reset link. This could allow them to gain control of your WordPress account, potentially leading to unauthorized access to your site, data theft, or further attacks on your users.

Compliance Impact

This vulnerability could lead to unauthorized access to user accounts, potentially exposing personal data. This may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information if user data is compromised.

Mitigation Strategies

Update the DynamicKit for Elementor plugin to version 1.0.3 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14596. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart