Description
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
Published: 2026-08-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows unauthenticated users to bypass the captcha mechanism provided by the Element Pack Elementor Addons plugin in WordPress. This bypass is an authentication control flaw, classified as CWE‑290, and permits attackers to submit forms or perform actions that the plugin originally required captcha confirmation for. The immediate consequence is the potential for indiscriminate spam or abuse, but no direct disclosure of sensitive data or code execution is indicated in the description.

Affected Systems

WordPress sites utilizing the bdthemes Element Pack Elementor Addons plugin version 8.7.13 or earlier are affected. The data does not reference any other vendors or products, so the impact is confined to this specific plugin on those versions.

Risk and Exploitability

The CVSS score of 5.3 places the issue in the medium severity range. No EPSS score is publicly available, and it is not listed in the CISA KEV catalog, suggesting limited known exploitation. The likely attack vector is a web‑based form submission that does not require prior user authentication, making exploitation straightforward and potentially viable through automated scripts. These conclusions are inferred from the description of the captcha bypass and the common exploitation methods for such vulnerabilities.

Generated by OpenCVE AI on August 6, 2026 at 16:48 UTC.

Remediation

Vendor Solution

Update the WordPress Element Pack Elementor Addons Plugin to the latest available version (at least 8.7.14).


OpenCVE Recommended Actions

  • Upgrade the Element Pack Elementor Addons plugin to version 8.7.14 or later.
  • If a patch cannot be applied immediately, disable the plugin or block unauthenticated access to the vulnerable form endpoints with a web‑application firewall.
  • Implement an additional captcha or anti‑spam rule on all site forms to mitigate the risk of abuse from unauthenticated submissions.

Generated by OpenCVE AI on August 6, 2026 at 16:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Bdthemes
Bdthemes element Pack Elementor Addons
Wordpress
Wordpress wordpress
Vendors & Products Bdthemes
Bdthemes element Pack Elementor Addons
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
Title WordPress Element Pack Elementor Addons plugin <= 8.7.13 - Captcha Bypass vulnerability
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Bdthemes Element Pack Elementor Addons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:22.645Z

Reserved: 2026-07-22T08:53:43.312Z

Link: CVE-2026-65502

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:00:11Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing