DynamicKit for Elementor < 1.0.3 - Unauthenticated Privilege Escalation via Account Takeover
criticalThe DynamicKit for Elementor plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to 1.0.3 (exclusive). This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to...
- CVSS:
- 9.8
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.3
- Disclosed:
- Aug 18, 2026