Access Control Flaw in ElementInvader Addons for Elementor by Element Invader
CVE-2026-25028
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 February 2026
What is CVE-2026-25028?
A missing authorization vulnerability in ElementInvader Addons for Elementor allows attackers to exploit incorrectly configured access control security levels. This flaw can enable unauthorized access to sensitive resources, making it imperative for users of affected versions (up to 1.4.1) to upgrade immediately to ensure their installations are secure.
Affected Version(s)
ElementInvader Addons for Elementor 0 <= 1.4.1