CVE-2026-65502: CWE-290 Authentication Bypass by Spoofing in bdthemes Element Pack Elementor Addons
CVE-2026-65502 is an authentication bypass vulnerability affecting Element Pack Elementor Addons versions up to and including 8.7.13. This flaw allows unauthenticated attackers to bypass authentication controls by spoofing, potentially leading to unauthorized actions. The vulnerability has a medium severity with a CVSS score of 5.3. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-65502) in Element Pack Elementor Addons (<= 8.7.13) is classified as CWE-290: Authentication Bypass by Spoofing. It enables unauthenticated attackers to bypass authentication mechanisms, potentially allowing unauthorized interactions with the affected plugin. The CVSS 3.1 base score is 5.3, reflecting a network attack vector with low complexity and no privileges or user interaction required. The vulnerability is published and tracked but lacks an official remediation level or patch information. The product is not a cloud service, so remediation depends on vendor patch releases.
Potential Impact
The impact is limited to unauthorized actions due to authentication bypass, with no direct confidentiality or availability impact reported. The medium severity score reflects that while the vulnerability can be exploited remotely without privileges, it does not lead to data disclosure or denial of service by itself. No active exploitation has been observed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or temporary workaround is documented, users should monitor vendor communications for updates. Until a patch is available, restricting access to the affected plugin or disabling it if feasible may reduce risk.
CVE-2026-65502: CWE-290 Authentication Bypass by Spoofing in bdthemes Element Pack Elementor Addons
Description
CVE-2026-65502 is an authentication bypass vulnerability affecting Element Pack Elementor Addons versions up to and including 8.7.13. This flaw allows unauthenticated attackers to bypass authentication controls by spoofing, potentially leading to unauthorized actions. The vulnerability has a medium severity with a CVSS score of 5.3. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.
CVSS v3.1
Score 5.3medium
Affected software
bdthemes
Element Pack Elementor Addons
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-65502) in Element Pack Elementor Addons (<= 8.7.13) is classified as CWE-290: Authentication Bypass by Spoofing. It enables unauthenticated attackers to bypass authentication mechanisms, potentially allowing unauthorized interactions with the affected plugin. The CVSS 3.1 base score is 5.3, reflecting a network attack vector with low complexity and no privileges or user interaction required. The vulnerability is published and tracked but lacks an official remediation level or patch information. The product is not a cloud service, so remediation depends on vendor patch releases.
Potential Impact
The impact is limited to unauthorized actions due to authentication bypass, with no direct confidentiality or availability impact reported. The medium severity score reflects that while the vulnerability can be exploited remotely without privileges, it does not lead to data disclosure or denial of service by itself. No active exploitation has been observed.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or temporary workaround is documented, users should monitor vendor communications for updates. Until a patch is available, restricting access to the affected plugin or disabling it if feasible may reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Patchstack
- Date Reserved
- 2026-07-22T08:53:43.312Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a749d37bf8831d539db9e75
Added to database: 08/06/2026, 14:41:59 UTC
Last enriched: 08/13/2026, 17:08:33 UTC
Last updated: 09/21/2026, 22:01:36 UTC
Views: 26
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.