SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-28164

CRITICAL · CVSS 9.6 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A critical Cross-Site Request Forgery (CSRF) vulnerability exists in HashThemes Easy Elementor Addons versions up to 2.3.7, potentially allowing attackers to execute unauthorized actions on behalf of authenticated users. Organizations using this plugin should prioritize patching or mitigating this vulnerability to prevent exploitation, as it poses a significant risk to user data and application integrity.

CVE
CVE-2026-28164
Severity
CRITICAL
CVSS
9.6
EPSS
0.15%

Original NVD Description

Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.