PT-2025-45081 · WordPress · Elementinvader Addons For Elementor
Lucas Montes
·
Published
2025-11-05
·
Updated
2025-11-05
·
CVE-2025-10873
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ElementInvader Addons for Elementor versions prior to 1.4.1
Description
The ElementInvader Addons for Elementor WordPress plugin is affected by a missing authorization check. An unauthenticated user can send arbitrary emails to arbitrary addresses through the
elementinvader addons for elementor forms send form action.Recommendations
Update ElementInvader Addons for Elementor to version 1.4.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elementinvader Addons For Elementor