VYPR
Medium severity5.4NVD Advisory· Published Feb 3, 2026· Updated Apr 15, 2026

CVE-2026-25028

CVE-2026-25028

Description

Missing Authorization vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ElementInvader Addons for Elementor: from n/a through <= 1.4.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in ElementInvader Addons for Elementor plugin (<=1.4.1) allows unauthenticated exploitation of access controls.

Vulnerability

Description The ElementInvader Addons for Elementor plugin for WordPress versions through 1.4.1 suffers from a missing authorization vulnerability. This flaw stems from incomplete access control checks, allowing attackers to exploit incorrectly configured security levels without proper authentication [1].

Exploitation

Attack Surface Attackers can trigger this vulnerability without any prior authentication, making it accessible to unauthenticated web visitors. The issue is particularly dangerous because it can be automated and used in mass-exploit campaigns targeting thousands of WordPress sites simultaneously [1].

Impact

Successful exploitation enables an unprivileged attacker to execute actions that should require higher privileges, such as modifying plugin settings or accessing sensitive data. The CVSS v3 base score of 5.4 indicates a medium severity, but the ease of exploitation raises practical risk [1].

Mitigation

The plugin vendor has released version 1.4.2, which addresses the missing authorization checks. Users are strongly advised to update immediately. For Patchstack users, enabling auto-updates for vulnerable plugins is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

1