PT-2026-21424 · WordPress+1 · The Plus Addons For Elementor+1

Quốc Huy

·

Published

2026-02-22

·

Updated

2026-02-22

·

CVE-2026-2385

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress versions through 6.4.7
Description The software contains a flaw due to insufficient verification of data authenticity. The plugin decrypts and trusts attacker-controlled email data in an unauthenticated AJAX handler without cryptographic authenticity guarantees. This allows attackers to manipulate form email routing and redirection values, potentially triggering unauthorized email relay and redirection via the email data parameter. The affected component is an AJAX handler.
Recommendations Update to version 6.4.8 or later.

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2026-2385

Affected Products

Elementor
The Plus Addons For Elementor