CVE-2026-81777: WordPress Essential Addons for Elementor plugin <= 6.8.0 - Bypass vulnerability vulnerability
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.
This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Essential Addons for Elementorto a version that resolves this vulnerability.Fixed in 6.8.1
Event History
Frequently Asked Questions
What level of access does an attacker need?
The CVSS vector indicates that exploitation can be performed over the network with no prior privileges and no user interaction. The attack complexity is rated low.
What is the expected security impact?
The issue enables identity spoofing and is rated as having low integrity impact. The provided scoring indicates no confidentiality or availability impact and no scope change.
How can I determine whether my installation is in the affected range?
Installations of WPDeveloper Essential Addons for Elementor with versions through 6.8.0 are identified as affected. The affected range begins at an unspecified earlier version.