Sceawere
Vulnerability Detail
CVE-2026-65502UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Element Pack Addons Unauthenticated Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 1d ago
- Vendor
- bdthemes
- Product
- Element Pack Elementor Addons
- Attack Type
- CWE-290 Authentication Bypass by Spoofing
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-08-06T15:17:14.573Z",
"pubdate": "2026-08-06T15:17:14.573Z",
"executiveSummary": "An unauthenticated bypass vulnerability has been identified in the Element Pack Elementor Addons plugin for WordPress, specifically affecting versions 8.7.13 and prior. This security flaw allows unauthenticated remote attackers to bypass access controls and potentially interact with restricted functionalities or sensitive endpoints exposed by the vulnerable plugin.\nThe vulnerability poses significant risk implications for web applications utilizing the affected software, as successful exploitation requires no prior privileges or user interaction, lowering the attack barrier entirely. Attackers operating over the network can leverage this flaw to subvert security mechanisms implemented within the plugin architecture.\nThe impact of this vulnerability depends on the specific exposed functionality within the vulnerable component, potentially leading to unauthorized data exposure, feature manipulation, or further secondary exploitation vectors within the WordPress environment. Organizations deploying the affected product face heightened exposure to automated scanning and targeted exploitation attempts until remedial actions are applied.\nMitigation requires immediate administrative action to update the Element Pack Elementor Addons plugin beyond the vulnerable version threshold, alongside continuous monitoring for anomalous HTTP requests targeting plugin-specific endpoints.",
"technicalDetails": "The vulnerability exists within the request handling and access control mechanisms of the Element Pack Elementor Addons plugin for versions <= 8.7.13. Specifically, the root cause stems from improper authorization checks or missing capability validations on sensitive hooks, AJAX actions, or REST API endpoints exposed by the plugin.\nNetwork exposure is direct, as the vulnerable component listens for incoming HTTP or HTTPS requests processed by the WordPress core framework. Because the flaw is unauthenticated, threat actors do not need to supply valid user session cookies, nonces, or administrative credentials to interact with the vulnerable code paths.\nThe attack flow proceeds as follows: First, an external attacker identifies the presence of the Element Pack Elementor Addons plugin on a target WordPress installation through reconnaissance techniques such as fingerprinting plugin-specific assets or paths. Next, the attacker formulates a crafted HTTP request directed at the inadequately protected endpoint or functionality. Due to the absence of rigorous authentication and privilege validation within the affected functions, the application processes the incoming payload as if it originated from an authorized context.\nUpon successful processing, the vulnerability allows the attacker to bypass intended security barriers, potentially granting unauthorized access to restricted features, data retrieval operations, or secondary execution flows handled by the plugin. Privilege requirements are nonexistent, and no complex exploitation prerequisites are necessary beyond network connectivity to the target web server.\nPost-exploitation impact correlates directly with the capabilities exposed by the bypassed component, which may facilitate information disclosure, unauthorized state modifications, or serve as a stepping stone for broader compromise of the underlying WordPress installation."
}