CVE-2025-39546: WordPress ElementsReady Addons for Elementor plugin <= 6.6.2 - Cross Site Request Forgery (CSRF) Vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in quomodosoft ElementsReady Addons for Elementor allows Cross Site Request Forgery. This issue affects ElementsReady Addons for Elementor: from n/a through 6.6.2.
Other sources
Cross-Site Request Forgery (CSRF) vulnerability in quomodosoft ElementsReady Addons for Elementor element-ready-lite allows Cross Site Request Forgery.This issue affects ElementsReady Addons for Elementor: from n/a through <= 6.6.2.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39546?
CVE-2025-39546 is considered a critical Cross-Site Request Forgery (CSRF) vulnerability.
How do I fix CVE-2025-39546?
To fix CVE-2025-39546, ensure that you update the ElementsReady Addons for Elementor to the latest version beyond 6.6.2.
Who is affected by CVE-2025-39546?
CVE-2025-39546 affects users of ElementsReady Addons for Elementor version 6.6.2 and earlier.
Can CVE-2025-39546 be exploited remotely?
Yes, CVE-2025-39546 can be exploited remotely due to its nature as a Cross-Site Request Forgery vulnerability.
What types of attacks can CVE-2025-39546 enable?
CVE-2025-39546 can enable attackers to perform unauthorized actions on behalf of users without their consent.