CVE-2026-28164: WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery.
This issue affects Easy Elementor Addons: from n/a through 2.3.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Easy Elementor Addonsto a version that resolves this vulnerability.Fixed in 2.3.8
Event History
Frequently Asked Questions
Which installations are affected?
Easy Elementor Addons versions through 2.3.7 are affected. The available data does not identify a fixed version.
What level of attacker access is required?
The CVSS vector indicates network-reachable exploitation with low attack complexity and no attacker privileges required. Exploitation does require user interaction, consistent with a CSRF attack.
What is the potential impact if exploited?
The issue is rated critical with a 9.6 CVSS score. The vector indicates high potential impact to confidentiality, integrity, and availability, with scope changed.