Executive brief
ElementsKit is a popular add-on for the Elementor website builder on WordPress, used to create custom headers, footers, and widgets. A security flaw in this plugin allows unauthorized individuals to bypass access controls due to incorrectly configured security levels. This could potentially lead to unauthorized access to certain site features or information, though it is currently rated as a low-priority threat.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Wpmet ElementsKit Elementor addons Lite plugin for WordPress. The flaw stems from incorrectly configured access control security levels within the plugin's functions. An unauthenticated remote attacker can exploit this lack of authorization checks to perform actions or access data that should be restricted to higher-privileged users. The vulnerability affects all versions up to and including 3.9.6. At the time of the advisory, no official patch has been confirmed, and users are advised to monitor for updates from the developer.
Affected products
- Wpmet ElementsKit Elementor addons Lite up to 3.9.6
Timeline
- 2026-01-18: other: Vulnerability reported by researcher Bonds
- 2026-05-27: advisory: Public advisory published by Patchstack and NVD