VYPR
Medium severity5.0NVD Advisory· Published May 20, 2026· Updated May 20, 2026

CVE-2026-45443

CVE-2026-45443

Description

Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in PDF for Elementor Forms plugin up to version 5.5.1 allows attackers to exploit incorrectly configured access controls.

Vulnerability

The vulnerability is a missing authorization (broken access control) in the PDF for Elementor Forms + Drag And Drop Template Builder plugin for WordPress. Affected versions from n/a through 5.5.1. The plugin fails to properly check permissions on certain functions, allowing exploitation of incorrectly configured access control security levels. [1]

Exploitation

An attacker does not require authentication or any special privileges. They can send crafted requests to the vulnerable endpoints to trigger actions that should be restricted to higher-privileged users. No user interaction is needed. The attack vector is network-based. [1]

Impact

Successful exploitation could lead to unauthorized access to sensitive data or functionality, potentially allowing the attacker to modify or delete PDF templates, access form submissions, or perform other actions normally reserved for administrators. The CVSS score is 5.0 (Medium), indicating moderate impact on confidentiality and integrity. [1]

Mitigation

The vulnerability is fixed in version 5.6.1, released on an unknown date but available from the WordPress plugin repository. Users should update immediately. For those unable to update, consider disabling the plugin or implementing additional access controls via a web application firewall. Patchstack users can enable auto-updates. [1]

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.