Description
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing.

This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
Published: 2026-08-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass flaw exists in WPDeveloper Essential Addons for Elementor that allows an attacker to spoof another user’s identity. The vulnerability stems from improper authorization checks within the plugin, as identified by CWE‑290. Because the attacker can claim another user’s credentials, potential damage ranges from unauthorized content publication to privilege escalation, depending on the roles available in the WordPress installation.

Affected Systems

The exploit affects the Essential Addons for Elementor plugin from the earliest public release through version 6.8.0. Any WordPress site that has installed this plugin within that version range is vulnerable. Users should verify the plugin version and confirm it is at least 6.8.1 before assuming safety.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity; however, the EPSS score is not available, so the exact likelihood of exploitation in the wild remains unclear. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet. The attack vector is likely through a crafted HTTP request to the plugin’s endpoint; based on the description, it is inferred that an attacker who can send authenticated requests to the site could trigger the bypass. Should exploitation occur, it would grant the attacker the permissions of the spoofed user, potentially enabling further attacks on the site.

Generated by OpenCVE AI on August 28, 2026 at 13:45 UTC.

Remediation

Vendor Solution

Update the WordPress Essential Addons for Elementor plugin to the latest available version (at least 6.8.1).


OpenCVE Recommended Actions

  • Update the Essential Addons for Elementor plugin to version 6.8.1 or later to eliminate the authorization flaw.
  • If updating immediately is not possible, consider disabling the plugin until the patch is applied to prevent exploitation.
  • After remediation, audit site activity logs and review user accounts for any anomalous actions that might indicate exploitation.

Generated by OpenCVE AI on August 28, 2026 at 13:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpdeveloper
Wpdeveloper essential Addons For Elementor
Vendors & Products Wordpress
Wordpress wordpress
Wpdeveloper
Wpdeveloper essential Addons For Elementor

Fri, 28 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
Title WordPress Essential Addons for Elementor plugin <= 6.8.0 - Bypass vulnerability vulnerability
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpdeveloper Essential Addons For Elementor
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-28T09:42:11.752Z

Reserved: 2026-08-27T12:24:25.082Z

Link: CVE-2026-81777

cve-icon Vulnrichment

Updated: 2026-08-28T15:27:56.053Z

cve-icon NVD

Status : Deferred

Published: 2026-08-28T12:16:32.487

Modified: 2026-08-28T15:09:00.790

Link: CVE-2026-81777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:30:17Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing