SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14596

HIGH · CVSS 8.8 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The DynamicKit for Elementor WordPress plugin prior to version 1.0.3 is vulnerable due to improper validation of user-supplied URLs in password-reset emails, enabling unauthenticated attackers to craft malicious reset links that can lead to account takeover. Organizations using this plugin should prioritize patching to mitigate the risk of unauthorized access to user accounts. This vulnerability poses a significant threat to any WordPress site utilizing the affected plugin.

CVE
CVE-2026-14596
Severity
HIGH
CVSS
8.8
EPSS
0.22%
WordPress

Original NVD Description

The DynamicKit for Elementor WordPress plugin before 1.0.3 does not validate the host of a user-supplied URL used as the base of the password-reset link it emails, allowing unauthenticated attackers to send a target user a legitimately-formatted reset email whose link points to an attacker-controlled host and carries a valid reset key, leading to account takeover when the victim clicks it.