PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 7, 2026

ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp Proxy

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-23693
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor (elementskit-lite) WordPress plugin versions prior to 3.7.9 expose the REST endpoint /wp-json/elementskit/v1/widget/mailchimp/subscribe without authentication. The endpoint accepts client-supplied Mailchimp API credentials and insufficiently validates certain parameters, including the list parameter, when constructing upstream Mailchimp API requests. An unauthenticated attacker can abuse the endpoint as an open proxy to Mailchimp, potentially triggering unauthorized API calls, manipulating subscription data, exhausting API quotas, or causing resource consumption on the affected WordPress site.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementorby Roxnor
AFFECTED< 3.7.9SAFE ✓≥ 3.7.9
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp Proxy CVE-2026-23693 Scanner | S4E