← Back to overview

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in HashThemes Easy Elementor Addons, a WordPress plugin. The vulnerability affects all versions of the plugin up to and including 2.3.7. Exploitation of this flaw could allow an attacker to perform unauthorized actions on behalf of authenticated users by tricking them into visiting a malicious page. The issue is tracked as CVE-2026-28164 and has been documented by both the NVD and Patchstack. No patch version lower bound is specified, indicating all prior releases may be affected. WordPress site administrators using this plugin are advised to update to a patched version as soon as one becomes available. The vulnerability is classified under CWE for CSRF attacks, which can lead to privilege escalation or data manipulation depending on the plugin's functionality.

Affected products

  • HashThemes Easy Elementor Addons

Related CVE's

  • CVE-2026-28164

Categories

  • Web Technologies