Executive brief
Essential Addons for Elementor is a popular WordPress plugin used to add advanced design elements to websites. A security flaw in versions prior to 6.6.0 allows unauthenticated users to bypass access controls, potentially enabling them to perform unauthorized actions on the site. While the impact is considered low, it could allow attackers to modify certain site settings or content without permission.
Technical details
A broken access control vulnerability exists in the Essential Addons for Elementor plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The vulnerability is reachable over the network without user interaction. While the CVSS score of 5.3 indicates a moderate risk, the lack of authentication makes it a candidate for automated scanning. The issue is resolved in version 6.6.0.
Affected products
- WPDeveloper Essential Addons for Elementor < 6.6.0
Timeline
- 2025-12-24: other: Reported by Que Thanh Tuan
- 2026-04-22: advisory: Patchstack advisory published
- 2026-06-15: disclosed: CVE published to NVD