External risk intelligence

Easy Elementor Addons Cross-Site Request Forgery Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-28164

The vulnerability affects a WordPress plugin, which is typically deployed as part of public-facing web applications. Because these plugins are active components of internet-accessible websites, they are commonly exposed to the public internet in standard deployments.

Cross-site Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This Cross-Site Request Forgery vulnerability affects a WordPress plugin used for website building, allowing unauthorized actions if users visit a malicious site. At a high level, this could enable attackers to perform actions as a user without their knowledge, potentially impacting website integrity. The main concern is confirming relevance and exposure.

  • Attackers can trick users into performing unwanted actions.
  • Websites using this plugin are potentially at risk.
  • Confirm if your organization uses this plugin.

Attack Path

How an attacker could exploit the issue

An attacker could trick a logged-in user into performing an unwanted action on a website using the Easy Elementor Addons plugin. This could happen if the user visits a malicious website or clicks a specially crafted link, leading to unauthorized changes to the website.

  • Requires no privileges or user interaction.
  • Triggers when a user visits a malicious link.
  • Allows unauthorized actions on the site.

Live Threat

Current exploitation, exposure, and threat context

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Easy Elementor Addons plugin when it is used in a supported configuration. This could allow an attacker to trick an authenticated user into performing unintended actions on the website without their knowledge or consent.

  • User actions on the website.
  • Via a malicious link or embedded content.
  • Unauthorized changes to website content or settings.

Operational Fix

Recommended remediation, mitigation, and detection steps

The HashThemes Easy Elementor Addons CSRF vulnerability requires immediate attention from teams managing public-facing WordPress sites. The first step is to identify all instances of this plugin, confirm if they are internet-accessible and critical to business operations, and then locate the specific owner responsible for the affected site or application to plan remediation.

  • Application owners should own the remediation.
  • Verify internet exposure and business criticality.
  • Coordinate vendor updates and plan maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the HashThemes Easy Elementor Addons plugin?

This plugin is a collection of widgets and features designed for the Elementor page builder, which runs on the WordPress content management system. Users install it to add visual elements like service blocks, team sections, and testimonials to their websites without writing code.

What does CWE-352 mean for CVE-2026-28164?

CWE-352 identifies this weakness as Cross-Site Request Forgery (CSRF). In simple terms, it means the plugin fails to verify that a request was intentionally sent by an authorized user, allowing a third party to trick a logged-in user into unknowingly performing actions, such as changing site settings or content.

How is this CSRF vulnerability triggered?

The flaw is triggered when an authenticated user—such as a site administrator—visits a malicious website or clicks a specially crafted link while they are logged into the WordPress dashboard. Importantly, the vulnerability does not trigger if there is no active session; an attacker cannot simply send a request to a site without the user first interacting with the malicious external content.

Do I need to worry if my site is internal?

Halo Surface Signal indicates that WordPress plugins are usually deployed on public-facing websites, making them inherently internet-accessible. If your site is strictly internal and unreachable from the outside, the risk of an attacker successfully luring your users to a malicious link is significantly lower than for sites exposed to the broader internet.

What are the first steps to address this CVE?

Start by auditing your WordPress environments to identify every installation of Easy Elementor Addons version 2.3.7 or earlier. Once identified, document which sites are internet-facing and assign responsibility to the specific application owners. Coordinate with these teams to prioritize maintenance and apply future vendor-provided updates to secure the plugin.

References