Junglewise Threat Intelligence

CVE-2026-42629: Powerpackelements PowerPack Pro for Elementor broken authentication

CVE-2026-42629 · Severity: high · CVSS 8.8 · Published 2026-06-17

Executive brief

PowerPack Pro for Elementor is a popular WordPress plugin used to add advanced design elements and widgets to websites. A security flaw in versions prior to 2.13.0 allows unauthenticated attackers to bypass authentication mechanisms, potentially leading to full administrative takeover of the website. This could result in the theft of customer data, site defacement, or the installation of malicious software.

Technical details

A broken authentication vulnerability (CWE-288) exists in the PowerPack Pro for Elementor plugin for WordPress in versions prior to 2.13.0. The flaw allows an unauthenticated attacker to bypass security checks via an alternate path or channel. While the attack is network-based and requires no initial privileges, successful exploitation requires a privileged user to perform an action, such as clicking a malicious link (User Interaction: Required). If successful, an attacker can perform actions with the permissions of higher-privileged users, potentially gaining full administrative access to the WordPress site. The issue is resolved in version 2.13.0.

Affected products

  • Powerpackelements PowerPack Pro for Elementor < 2.13.0

Timeline

  • 2026-04-03: other: Vulnerability reported by Nguyen Ba Khanh
  • 2026-04-29: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: CVE published to NVD

References