Junglewise Threat Intelligence

CVE-2026-81777: WPDeveloper Essential Addons for Elementor authentication bypass

CVE-2026-81777 · Severity: medium · CVSS 5.3 · Published 2026-08-28

Technologies: WPDeveloper Essential Addons for Elementor. Vendors: WPDeveloper.

Executive brief

Essential Addons for Elementor is a widely-used WordPress plugin that extends the Elementor page builder with additional content elements and functionality. An authentication bypass vulnerability allows attackers to spoof user identity and bypass security controls without requiring valid credentials, potentially leading to unauthorized access and account impersonation on affected websites.

Technical details

The vulnerability is an authentication bypass flaw in Essential Addons for Elementor that permits attackers to bypass security checks through identity spoofing. The issue affects versions through 6.8.0 and requires no authentication or special privileges to exploit. An attacker can circumvent authentication mechanisms to assume the identity of legitimate users, enabling unauthorized actions such as content manipulation or privilege escalation. The vulnerability was patched in version 6.8.1. The attack vector is network-based and does not require user interaction.

Affected products

  • WPDeveloper Essential Addons for Elementor through 6.8.0

Timeline

  • 2026-08-27: disclosed
  • 2026-08-27: patched: Version 6.8.1

References

Related threats