5.3
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
The ElementInvader Addons for Elementor WordPress plugin before 1.4.1 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses due to missing authorization on the elementinvader_addons_for_elementor_forms_send_form action.
Basic Information
ID
CVE-2025-10873
Source
WPScan
Published
Nov 5, 2025 at 06:00
Modified
Nov 5, 2025 at 18:38
Affected Product
Vendor
Unknown
Product
ElementInvader Addons for Elementor
Affected Versions
Unknown ElementInvader Addons for Elementor 0