What is CVE-2026-13392?
CVE-2026-13392 is a critical vulnerability in the ElementsKit Elementor Addons plugin. It allows users with administrative privileges to save custom widget definitions directly into a generated PHP file, leading to potential Remote Code Execution. Immediate update to version 3.10.01 or later is strongly recommended.
Azərbaycanca: CVE-2026-13392 ElementsKit Elementor Addons plaginində aşkar edilmiş kritik boşluqdur. Administrator səlahiyyətli istifadəçilərin xüsusi widget təriflərini birbaşa PHP faylına yazaraq uzaqdan kod icrasına (Remote Code Execution) səbəb ola bilər. Təhlükəsizliyi təmin etmək üçün plaqini dərhal 3.10.01 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What level of access is required to exploit CVE-2026-13392?
Administrative privileges are required to exploit this vulnerability.
To which version should the ElementsKit Elementor Addons plugin be updated to fix CVE-2026-13392?
The plugin should be updated to version 3.10.01 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.