Cross-Site Request Forgery Vulnerability in HashThemes Easy Elementor Addons
CVE-2026-28164
9.6CRITICAL
What is CVE-2026-28164?
The HashThemes Easy Elementor Addons plugin is susceptible to Cross-Site Request Forgery attacks. An attacker can exploit this vulnerability to perform unauthorized actions on behalf of authenticated users, potentially compromising user accounts and sensitive information. The affected versions range from n/a to 2.3.7, making it crucial for users to update to the latest security patches to mitigate this risk.
Affected Version(s)
Easy Elementor Addons <= 2.3.7