Junglewise Threat Intelligence

CVE-2026-49052: Wpmet ElementsKit Elementor addons Lite missing authorization

CVE-2026-49052 · Severity: medium · CVSS 4.3 · Published 2026-05-27

Executive brief

ElementsKit Elementor addons Lite is a popular WordPress plugin used to add custom widgets and features to websites built with the Elementor page builder. A security flaw in the plugin's access control settings allows users with low-level accounts, such as contributors, to perform actions they should not be authorized to do. While the immediate risk to data or site availability is considered low, it could allow unauthorized changes to site configurations or content.

Technical details

A missing authorization vulnerability (CWE-862) exists in Wpmet ElementsKit Elementor addons Lite through version 3.9.6. The flaw stems from incorrectly configured access control security levels within the plugin's functional components. An authenticated attacker with 'Contributor' level privileges can exploit this lack of server-side authorization checks to execute functions or modify settings that should be restricted to higher-privileged users. The attack is reachable over the network and does not require user interaction, though it does require a valid low-level user account. As of the advisory date, no official patch has been confirmed.

Affected products

  • Wpmet ElementsKit Elementor addons Lite up to 3.9.6

Timeline

  • 2026-01-18: other: Reported by researcher Bonds
  • 2026-05-27: advisory: Published by Patchstack and NVD

References

Related threats