Sceawere

Vulnerability Detail

CVE-2026-65502UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Element Pack Addons Unauthenticated Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1d ago
Vendor
bdthemes
Product
Element Pack Elementor Addons
Attack Type
CWE-290 Authentication Bypass by Spoofing
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-06T15:17:14.573Z",
  "pubdate": "2026-08-06T15:17:14.573Z",
  "executiveSummary": "An unauthenticated bypass vulnerability has been identified in the Element Pack Elementor Addons plugin for WordPress, specifically affecting versions 8.7.13 and prior. This security flaw allows unauthenticated remote attackers to bypass access controls and potentially interact with restricted functionalities or sensitive endpoints exposed by the vulnerable plugin.\nThe vulnerability poses significant risk implications for web applications utilizing the affected software, as successful exploitation requires no prior privileges or user interaction, lowering the attack barrier entirely. Attackers operating over the network can leverage this flaw to subvert security mechanisms implemented within the plugin architecture.\nThe impact of this vulnerability depends on the specific exposed functionality within the vulnerable component, potentially leading to unauthorized data exposure, feature manipulation, or further secondary exploitation vectors within the WordPress environment. Organizations deploying the affected product face heightened exposure to automated scanning and targeted exploitation attempts until remedial actions are applied.\nMitigation requires immediate administrative action to update the Element Pack Elementor Addons plugin beyond the vulnerable version threshold, alongside continuous monitoring for anomalous HTTP requests targeting plugin-specific endpoints.",
  "technicalDetails": "The vulnerability exists within the request handling and access control mechanisms of the Element Pack Elementor Addons plugin for versions <= 8.7.13. Specifically, the root cause stems from improper authorization checks or missing capability validations on sensitive hooks, AJAX actions, or REST API endpoints exposed by the plugin.\nNetwork exposure is direct, as the vulnerable component listens for incoming HTTP or HTTPS requests processed by the WordPress core framework. Because the flaw is unauthenticated, threat actors do not need to supply valid user session cookies, nonces, or administrative credentials to interact with the vulnerable code paths.\nThe attack flow proceeds as follows: First, an external attacker identifies the presence of the Element Pack Elementor Addons plugin on a target WordPress installation through reconnaissance techniques such as fingerprinting plugin-specific assets or paths. Next, the attacker formulates a crafted HTTP request directed at the inadequately protected endpoint or functionality. Due to the absence of rigorous authentication and privilege validation within the affected functions, the application processes the incoming payload as if it originated from an authorized context.\nUpon successful processing, the vulnerability allows the attacker to bypass intended security barriers, potentially granting unauthorized access to restricted features, data retrieval operations, or secondary execution flows handled by the plugin. Privilege requirements are nonexistent, and no complex exploitation prerequisites are necessary beyond network connectivity to the target web server.\nPost-exploitation impact correlates directly with the capabilities exposed by the bypassed component, which may facilitate information disclosure, unauthorized state modifications, or serve as a stepping stone for broader compromise of the underlying WordPress installation."
}
CVE-2026-65502: Element Pack Addons Unauthenticated Bypass Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere