PT-2026-67045 · WordPress · Dynamickit For Elementor
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DynamicKit for Elementor versions prior to 1.0.3
Description
An issue exists where the plugin fails to validate the host of a user-supplied URL used as the base for password-reset emails. This allows unauthenticated attackers to send a target user a legitimately formatted reset email containing a valid reset key, but with a link pointing to a host controlled by the attacker. If the victim clicks the link, it can lead to account takeover.
Recommendations
Update DynamicKit for Elementor to version 1.0.3 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dynamickit For Elementor