Impact
The vulnerability is a cross‑site request forgery flaw that permits an attacker to inject forged HTTP requests to the WordPress Easy Elementor Addons plugin. By exploiting this weakness, a malicious actor can perform state‑changing actions on the site that the targeted user is authorized to execute, potentially compromising data confidentiality, integrity, and availability. The weakness is classified as CWE‑352 and carries a CVSS score of 9.6, indicating a critical severity level.
Affected Systems
This flaw affects the HashThemes Easy Elementor Addons plugin for WordPress, any release up through version 2.3.7. Versions 2.3.8 and later contain the fix.
Risk and Exploitability
The CVSS score of 9.6 reflects a high likelihood of significant impact, although the EPSS score is not available. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a forged request issued by a user’s browser, either by tricking the user into visiting a malicious link or by sending a crafted request from the attacker’s own environment. Exploitation requires an authenticated user context or the ability to force a user to submit a state‑changing request, and can allow the attacker to carry out unauthorized actions on the website.
OpenCVE Enrichment