CVE-2026-49053: WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulnerability
Published May 27, 2026
·Updated
Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects ElementsKit Elementor addons Lite: from n/a through 3.9.6.
Affected Software
1 affected component
Wpmet ElementsKit Elementor addons Lite<=3.9.6
Event History
May 27, 2026
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-49053?
The severity of CVE-2026-49053 is medium with a score of 5.3.
2
What is CVE-2026-49053 about?
CVE-2026-49053 is a Broken Access Control vulnerability in the ElementsKit Elementor addons Lite plugin.
3
How do I fix CVE-2026-49053?
To fix CVE-2026-49053, update the ElementsKit Elementor addons Lite plugin to version 3.9.7 or later.
4
Which versions are affected by CVE-2026-49053?
CVE-2026-49053 affects all versions of ElementsKit Elementor addons Lite from n/a up to and including 3.9.6.
5
What can happen if CVE-2026-49053 is exploited?
If exploited, CVE-2026-49053 can lead to unauthorized access due to incorrectly configured access control levels.