PT-2026-21424 · WordPress+1 · The Plus Addons For Elementor+1

Quốc Huy

·

Publicado

2026-02-22

·

Atualizado

2026-02-22

·

CVE-2026-2385

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress versions through 6.4.7
Description The software contains a flaw due to insufficient verification of data authenticity. The plugin decrypts and trusts attacker-controlled email data in an unauthenticated AJAX handler without cryptographic authenticity guarantees. This allows attackers to manipulate form email routing and redirection values, potentially triggering unauthorized email relay and redirection via the email data parameter. The affected component is an AJAX handler.
Recommendations Update to version 6.4.8 or later.

Correção

Insufficient Verification of Data Authenticity

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2385

Produtos afetados

Elementor
The Plus Addons For Elementor