Cross-Site Request Forgery Vulnerability in HashThemes Easy Elementor Addons
CVE-2026-28164

9.6CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2026

What is CVE-2026-28164?

The HashThemes Easy Elementor Addons plugin is susceptible to Cross-Site Request Forgery attacks. An attacker can exploit this vulnerability to perform unauthorized actions on behalf of authenticated users, potentially compromising user accounts and sensitive information. The affected versions range from n/a to 2.3.7, making it crucial for users to update to the latest security patches to mitigate this risk.

Affected Version(s)

Easy Elementor Addons <= 2.3.7

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Asim Alshaya | Patchstack Bug Bounty Program
.