Junglewise Threat Intelligence

CVE-2026-14596: DynamicKit for Elementor account takeover via password reset host injection

CVE-2026-14596 · Severity: info · CVSS 8.8 · Published 2026-08-01

Executive brief

DynamicKit for Elementor, a WordPress plugin used to enhance page building capabilities, contains a security flaw in its password reset process. An attacker can trigger a password reset email to a user that contains a link pointing to a malicious website instead of the legitimate site. If the user clicks this link, the attacker can capture their secret reset key and take full control of their account.

Technical details

The DynamicKit for Elementor plugin fails to validate the host component of a user-supplied URL when generating password reset emails. An unauthenticated remote attacker can inject an arbitrary host into the reset link generation process. When a targeted user receives the legitimately-formatted email and clicks the link, the valid password reset token is transmitted to the attacker-controlled server. This allows the attacker to use the captured token to reset the victim's password and gain full access to the account. The vulnerability is fixed in version 1.0.3.

Affected products

  • Unknown DynamicKit for Elementor < 1.0.3

Timeline

  • 2026-07-17: disclosed: Publicly published on WPScan
  • 2026-08-01: advisory: NVD publication date
  • 2026-08-01: patched: Fixed in version 1.0.3

References