Impact
CVE-2026‑22350 describes a missing authorization flaw (CWE‑862) in the add‑ons.org PDF for Elementor Forms + Drag And Drop Template Builder plugin. The vulnerability permits exploitation of incorrectly configured access control security levels, potentially allowing an attacker to access or use functionality that should be restricted. The description does not specify whether PDF files, form data, or other plugin features are exposed; the impact is therefore limited to unauthorized access to the affected functionality.
Affected Systems
WordPress sites that have the add‑ons.org PDF for Elementor Forms + Drag And Drop Template Builder plugin installed, versions from the initial release through 6.3.1, are affected. Any installation that has not yet updated to a fixed version remains vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of widespread exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description of a missing authorization check, it is inferred that an attacker would need only to send requests to the plugin’s endpoints via the web interface without proper authentication. The exact method of exploitation is not detailed in the CVE data.
OpenCVE Enrichment