/Vulnerability Library

ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp Proxy

CVE-2026-23693
Verified

Description

The ElementsKit Elementor Addons Lite (elementskit-lite) plugin for WordPress before 3.7.9 registers the REST route /wp-json/elementskit/v1/widget/mailchimp/subscribe with no authentication or capability check (CWE-306). The handler accepts client-supplied Mailchimp API credentials and a `list` parameter and issues upstream Mailchimp API requests, letting an unauthenticated attacker use the site as an open proxy to Mailchimp.

Severity

High

CVSS Score

10

Exploit Probability

1%

Affected Product

elementskit-lite

Published Date

September 7, 2026

Template Author

rahulreddykarne

CVE-2026-23693.yaml
10.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
CVE ID:
cve-2026-23693
CWE ID:
cwe-306

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/85025fb9-6e19-4c0f-bf16-4b890ba5f7f5https://wordpress.org/plugins/elementskit-lite/https://nvd.nist.gov/vuln/detail/CVE-2026-23693

Remediation Steps

Update ElementsKit Lite (elementskit-lite) to 3.7.9 or later, which enforces authentication on the endpoint.