CVE-2026-45443
Description
Missing Authorization vulnerability in ADD-ONS.ORG PDF for Elementor Forms + Drag And Drop Template Builder allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects PDF for Elementor Forms + Drag And Drop Template Builder: from n/a through 5.5.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in PDF for Elementor Forms plugin up to version 5.5.1 allows attackers to exploit incorrectly configured access controls.
Vulnerability
The vulnerability is a missing authorization (broken access control) in the PDF for Elementor Forms + Drag And Drop Template Builder plugin for WordPress. Affected versions from n/a through 5.5.1. The plugin fails to properly check permissions on certain functions, allowing exploitation of incorrectly configured access control security levels. [1]
Exploitation
An attacker does not require authentication or any special privileges. They can send crafted requests to the vulnerable endpoints to trigger actions that should be restricted to higher-privileged users. No user interaction is needed. The attack vector is network-based. [1]
Impact
Successful exploitation could lead to unauthorized access to sensitive data or functionality, potentially allowing the attacker to modify or delete PDF templates, access form submissions, or perform other actions normally reserved for administrators. The CVSS score is 5.0 (Medium), indicating moderate impact on confidentiality and integrity. [1]
Mitigation
The vulnerability is fixed in version 5.6.1, released on an unknown date but available from the WordPress plugin repository. Users should update immediately. For those unable to update, consider disabling the plugin or implementing additional access controls via a web application firewall. Patchstack users can enable auto-updates. [1]
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<=5.5.1+ 1 more
- (no CPE)range: <=5.5.1
- (no CPE)range: <=5.5.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.