CVE-2026-2385General

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in all versions up to, and including, 6.4.7. This is due to the plugin decrypting and trusting attacker-controlled email_data in an unauthenticated AJAX handler without cryptographic authenticity guarantees. This makes it possible for unauthenticated attackers to tamper with form email routing and redirection values to trigger unauthorized email relay and attacker-controlled redirection via the 'email_data' parameter.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-22: 2Patch / Workaround · 2026-02-22: 1Technical Details · 2026-02-22: 102-22
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-2385 The The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Insufficient Verificatio… https://www.cve.org/CVERecord?id=CVE-2026-2385

    Post summary

    The text merely cites CVE‑2026‑2385 with a brief, non‑specific mention of a vulnerability, offering no further technical, exploit, or mitigation details.

    00000108
    56.5K followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-2385: The Plus Addons for Elementor WordPress plugin lets anyone reroute site emails via an unauthenticated AJAX call. Update to 6.4.8+ now! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-2385 #WordPress #infosec #EmailSecurity

    Post summary

    CVE-2026-2385 permits unauthenticated email rerouting through an AJAX call; updating to version 6.4.8+ mitigates the issue.

    0000049
    51 followersView on X

Explore more