Impact
Missing authorization in Easy Elementor Addons allows requesters to bypass intended security controls and access restricted administrative or configuration areas of the plugin. Attackers could read or modify plugin settings, inject content, or otherwise manipulate the plugin’s behavior in ways that were not permitted for their user level.
Affected Systems
Any WordPress site that has the hashthemes Easy Elementor Addons plugin version 2.2.7 or earlier installed is vulnerable. The issue is not tied to a specific server configuration or plugin version beyond the stated limit.
Risk and Exploitability
The CVSS score of 4.3 signals a moderate impact from a technical standpoint. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw is a broken access control, even a low‑impact exploitation vector could allow users with minimal privileges to perform unauthorized actions if the plugin’s configuration permits such operations.
OpenCVE Enrichment
EUVD