ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp Proxy
CVE-2026-23693
Verified
Description
The ElementsKit Elementor Addons Lite (elementskit-lite) plugin for WordPress before 3.7.9 registers the REST route /wp-json/elementskit/v1/widget/mailchimp/subscribe with no authentication or capability check (CWE-306). The handler accepts client-supplied Mailchimp API credentials and a `list` parameter and issues upstream Mailchimp API requests, letting an unauthenticated attacker use the site as an open proxy to Mailchimp.
Severity
High
CVSS Score
10
Exploit Probability
1%
Affected Product
elementskit-lite
Published Date
September 7, 2026
Template Author
rahulreddykarne
CVE-2026-23693.yaml
10.0Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
CVE ID:
cve-2026-23693
CWE ID:
cwe-306
Remediation Steps
Update ElementsKit Lite (elementskit-lite) to 3.7.9 or later, which enforces authentication on the endpoint.