AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-23693

CRITICAL · CVSS 10 EPSS 0.38%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-02-23 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 10.0. It affects WordPress. Exploitation may require the attacker to be authenticated.

CVE
CVE-2026-23693
Severity
CRITICAL
CVSS
10
EPSS
0.38%
WordPress

Original NVD Description

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open proxy to Mailchimp, potentially triggering unauthorized API calls, manipulating subscription data, exhausting API quotas, or causing resource consumption on the affected WordPress site.