Impact
An authentication bypass flaw exists in WPDeveloper Essential Addons for Elementor that allows an attacker to spoof another user’s identity. The vulnerability stems from improper authorization checks within the plugin, as identified by CWE‑290. Because the attacker can claim another user’s credentials, potential damage ranges from unauthorized content publication to privilege escalation, depending on the roles available in the WordPress installation.
Affected Systems
The exploit affects the Essential Addons for Elementor plugin from the earliest public release through version 6.8.0. Any WordPress site that has installed this plugin within that version range is vulnerable. Users should verify the plugin version and confirm it is at least 6.8.1 before assuming safety.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; however, the EPSS score is not available, so the exact likelihood of exploitation in the wild remains unclear. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet. The attack vector is likely through a crafted HTTP request to the plugin’s endpoint; based on the description, it is inferred that an attacker who can send authenticated requests to the site could trigger the bypass. Should exploitation occur, it would grant the attacker the permissions of the spoofed user, potentially enabling further attacks on the site.
OpenCVE Enrichment