The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-super subsite Administrator, who is otherwise denied code/file editing, reach host-level code execution beyond the privileges the network grants them.
We have discovered 166,444 live websites that are affected by CVE-2026-13392.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 166,444 live websites (100% of ElementsKit install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 136 versions ( 100% of all versions) |
| 44,347 websites | |
| 13,050 websites | |
| 10,201 websites | |
| 10,177 websites | |
| 7,710 websites | |
| 7,567 websites | |
| 5,605 websites | |
| 5,297 websites | |
| 5,119 websites | |
| 4,423 websites |
| .com | 73,730 websites |
| .com.br | 9,346 websites |
| .org | 7,091 websites |
| .de | 5,778 websites |
| .co.uk | 3,836 websites |
| .it | 3,683 websites |
| .net | 3,495 websites |
| .pl | 3,347 websites |
| .fr | 3,306 websites |
| .nl | 2,872 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | *,*** | ||
| ****************.com | **,*** | ||
| ********.***.br | **,*** | ||
| **********.com | **,*** | ||
| ******.com | **,*** | ||
| ******.com | **,*** | ||
| *****.io | **,*** | ||
| *****************.com | **,*** | ||
| ******************.com | **,*** | ||
| ********.com | **,*** |
FAQ