Access Control Flaw in News Kit Elementor Addons by BlazeThemes
CVE-2026-25416
4.3MEDIUM
What is CVE-2026-25416?
A missing authorization vulnerability exists in the News Kit Elementor Addons by BlazeThemes. This flaw allows attackers to exploit incorrectly configured access control security levels, potentially gaining unauthorized access to sensitive functionality within the plugin. This issue affects versions up to and including 1.4.2, making it crucial for users to update to the latest version to ensure their systems remain secure.
Affected Version(s)
News Kit Elementor Addons 0 <= 1.4.2