CVE-2026-4326Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability check does not terminate execution when it fails — it only sets an error message variable while allowing the plugin installation and activation code to execute. The error response is only sent after the installation and activation have already completed. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins from the WordPress.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 5 mentions (2026-04-09); latest day: 1
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01345Mentions · 2026-04-09: 5Mentions · 2026-04-18: 1Patch / Workaround · 2026-04-18: 1Technical Details · 2026-04-09: 4Technical Details · 2026-04-18: 104-0904-18
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-095
Disclosure5
2026-04-181
Patch1
Full discourse6 posts
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    🚨 HIGH: CVE-2026-4326 (CVSS 8.8) - Vertex Addons for Elementor plugin ≤1.6.4 vulnerable to Missing Authorization. Subscribers can install/activate arbitrary plugins. Patch immediately. #CVE #Vulnerability #PatchNow #WordPress https://t.co/XIklYuZxWC

    Post summary

    The message announces a high‑severity vulnerability (CVE‑2026‑4326) affecting Vertex Addons for Elementor, calls for immediate patching, and provides basic technical details.

    0000080
    25 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4326 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4326 #CVE-2026-4326 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/B9fJVsIj0g

    Post summary

    The tweet announces the new CVE-2026-4326 affecting WordPress with a severity score of 8.8 and high risk level, providing no exploit details or mitigation information.

    0000044
    123 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4326 The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authoriza… https://www.cve.org/CVERecord?id=CVE-2026-4326 ----- Traducción: CVE-2026-4326 El … http://infoflow.cloud`

    Post summary

    CVE-2026-4326 is disclosed as a missing authorization vulnerability affecting the Vertex Addons for Elementor plugin for WordPress up to version 1.6.4, with no PoC, exploit, patch, or active exploitation evidence provided.

    0000045
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4326 The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authoriza… https://www.cve.org/CVERecord?id=CVE-2026-4326

    Post summary

    This post announces a missing‑authorization flaw in the Vertex Addons for Elementor WordPress plugin, impacting versions up to 1.6.4, without providing any PoC, exploit, or patch details.

    00000177
    57.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4326: HIGH] Vulnerable Vertex Addons for Elementor plugin allows authenticated attackers to install & activate arbitrary plugins due to improper authorization enforcement in versions up to 1.6.4.#cve,CVE-2026-4326,#cybersecurity https://cvefind.com/CVE-2026-4326

    Post summary

    The post announces CVE-2026-4326, detailing that authenticated attackers can install arbitrary plugins in the Elementor plugin up to version 1.6.4 due to improper authorization enforcement, with no mention of patches or exploitation activity.

    0000053
    619 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4326 Missing Authorization in Vertex Addons for Elementor Plugin Up To ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4326 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The post announces CVE‑2026‑4326, describing a missing‑authorization flaw in a WordPress plugin and provides a link to a vulnerability database page, but offers no PoC, exploit code, patches, or evidence of active exploitation.

    0000037
    4.0K followersView on X

Explore more