PT-2026-21424 · WordPress+1 · The Plus Addons For Elementor+1
Quốc Huy
·
Published
2026-02-22
·
Updated
2026-02-22
·
CVE-2026-2385
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress versions through 6.4.7
Description
The software contains a flaw due to insufficient verification of data authenticity. The plugin decrypts and trusts attacker-controlled
email data in an unauthenticated AJAX handler without cryptographic authenticity guarantees. This allows attackers to manipulate form email routing and redirection values, potentially triggering unauthorized email relay and redirection via the email data parameter. The affected component is an AJAX handler.Recommendations
Update to version 6.4.8 or later.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elementor
The Plus Addons For Elementor