CVE-2026-23693Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open proxy to Mailchimp, potentially triggering unauthorized API calls, manipulating subscription data, exhausting API quotas, or causing resource consumption on the affected WordPress site.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 8 classified signals
  • Peaked 4d ago at 4 mentions (2026-02-23); latest day: 1
  • 9 total mentions across 5 days

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-02-23: 4Mentions · 2026-02-24: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-09-07: 1Patch / Workaround · 2026-02-24: 2Technical Details · 2026-02-23: 4Technical Details · 2026-02-24: 2Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-09-07: 102-2302-2402-2702-2809-07
Signal classification2 categories
Disclosure
888.9%
Patch
111.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-234
Disclosure4
2026-02-242
Disclosure1Patch1
2026-02-271
Disclosure1
2026-02-281
Disclosure1
2026-09-071
Disclosure1
Full discourse9 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-23693 - high 🚨 ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp Proxy > The ElementsKit Elementor Addons Lite (elementskit-lite) plugin for WordPress before ... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-23693 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces high‑severity CVE‑2026‑23693 affecting ElementsKit Lite <3.7.9, noting an unauthenticated Mailchimp proxy flaw, without providing PoC, exploit code, or patch details.

    00001443
    1.3K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-23693 - Critical ElementsKit Lite (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoi... https://www.thehackerwire.com/vulnerability/CVE-2026-23693/ https://t.co/vnz08Erg0k

    Post summary

    The post announces a critical vulnerability in ElementsKit Lite WordPress plugin that allows unauthenticated access to a REST endpoint.

    0000182
    113 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-23693 (CVSS:9.3, CRITICAL) is Awaiting Analysis. ElementsKit Elementor Addons – Advanced Widgets &amp; Templates Addons for Elementor (elementskit-lite) WordPress plugin ver..https://nvd.nist.gov/vuln/detail/CVE-2026-23693 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces a new critical vulnerability (CVE-2026-23693) affecting the ElementsKit Elementor Addons for WordPress, providing its CVSS score but no details on exploitation, patches, or PoCs.

    0000029
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-23693 (CVSS:9.3, CRITICAL) is Awaiting Analysis. ElementsKit Elementor Addons – Advanced Widgets &amp; Templates Addons for Elementor (elementskit-lite) WordPress plugin ver..https://nvd.nist.gov/vuln/detail/CVE-2026-23693 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2026-23693 is a newly disclosed critical vulnerability in the ElementsKit Elementor Addons plugin, with no public PoC, exploit, or patch information available yet, and it remains under analysis.

    0000025
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23693 ElementsKit Lite (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authe… https://www.cve.org/CVERecord?id=CVE-2026-23693

    Post summary

    CVE-2026-23693 exposes an unauthenticated REST endpoint in ElementsKit Lite WordPress plugin versions before 3.7.9, and the issue is fixed in version 3.7.9.

    00000133
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: CVE-2026-23693 in ElementsKit Lite &lt;3.7.9 exposes an unauth’d Mailchimp REST endpoint — risking API abuse &amp; resource drain. Update ASAP &amp; restrict /wp-json/elementskit/v1/widget/mailchimp/subscribe. https://radar.offseq.com/threat/cve-2026-23693-cwe-306-missing-aut... https://t.co/P27Qahl9JC

    Post summary

    CVE-2026-23693 is a critical flaw in ElementsKit Lite that exposes an unauthenticated Mailchimp REST endpoint, enabling potential API abuse; users are urged to update immediately and restrict the endpoint.

    0000053
    269 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23693 Unauthenticated Mailchimp API Proxy Vulnerability in ElementsKit Lite WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23693

    Post summary

    The text announces CVE-2026-23693, an unauthenticated Mailchimp API proxy vulnerability in ElementsKit Lite WordPress Plugin, without providing details on exploitation or mitigation.

    0000073
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-23693: CRITICAL] Vulnerability in ElementsKit Lite WordPress plugin (prior to 3.7.9) exposes REST endpoint wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication, allowing potenti...#cve,CVE-2026-23693,#cybersecurity https://cvefind.com/CVE-2026-23693

    Post summary

    A critical vulnerability in ElementsKit Lite WordPress plugin (prior to 3.7.9) exposes an unauthenticated REST endpoint, potentially allowing malicious actions.

    0000084
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-23693** pertains to a critical security flaw in the **ElementsKit Lite** WordPress plugin (version prior to 3.7.9). The vulnerability involves an **unauthenticated REST API endpoint** (`/wp-json/elementskit/v1/widget/mailchimp/subscribe`) that allows attackers to send requests without any form of authentication or authorization. This endpoint accepts Mailchimp API credentials supplied by the client and constructs API requests to Mailchimp's servers. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #DDoS https://cvetodo.com/cve/CVE-2026-23693

    Post summary

    The post announces CVE-2026-23693, a critical flaw in ElementsKit Lite that exposes an unauthenticated REST API endpoint allowing attackers to use supplied Mailchimp credentials to send requests to Mailchimp servers.

    0000074
    20 followersView on X

Explore more