CVE-2026-25398: WordPress Vertex Addons for Elementor plugin <= 1.6.4 - Broken Access Control vulnerability
Published Mar 25, 2026
·Updated
Missing Authorization vulnerability in Webilia Inc. Vertex Addons for Elementor addons-for-elementor-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Vertex Addons for Elementor: from n/a through <= 1.6.4.
Affected Software
1 affected component
Webilia Vertex Addons for Elementor<=1.6.4
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-25398?
The severity of CVE-2026-25398 is classified as medium with a CVSS score of 6.5.
2
How do I fix CVE-2026-25398?
To fix CVE-2026-25398, update the WordPress Vertex Addons for Elementor plugin to a version greater than 1.6.4.
3
What type of vulnerability is CVE-2026-25398?
CVE-2026-25398 is characterized as a Broken Access Control vulnerability.
4
Which versions of the software are affected by CVE-2026-25398?
CVE-2026-25398 affects the Vertex Addons for Elementor plugin versions from n/a through 1.6.4.
5
Who is impacted by CVE-2026-25398?
Users of the Vertex Addons for Elementor plugin who have versions 1.6.4 or lower are impacted by CVE-2026-25398.