What is CVE-2026-14596?
This vulnerability exists in DynamicKit for Elementor plugin versions before 1.0.3. An unauthenticated attacker can manipulate the host of the password-reset link sent via email, redirecting the victim to an attacker-controlled site while the email appears legitimate. Updating to version 1.0.3 or later is strongly recommended.
Azərbaycanca: Bu boşluq DynamicKit for Elementor plaqininin 1.0.3-dən əvvəlki versiyalarında aşkarlanıb. Authenticated olmayan hücumçu, istifadəçinin e-poçt ünvanına göndərilən şifrə sıfırlama linkinin host hissəsini manipulyasiya edərək qurbanı öz nəzarətindəki zərərli sayta yönləndirə bilər. Plaqini ən azı 1.0.3 versiyasına yeniləmək tövsiyə olunur.
FAQ1
How is the CVE-2026-14596 vulnerability in DynamicKit for Elementor exploited?
An unauthenticated attacker manipulates the host of the password-reset link sent via email. This makes the email appear legitimate, but the victim is redirected to an attacker-controlled site.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.