ElementInvader Addons for Elementor WordPress Plugin Missing Authorization Vulnerability Allowing Unauthenticated Arbitrary Email Sending

Vulnerability

A vulnerability exists in the ElementInvader Addons for Elementor WordPress plugin in versions prior to 1.4.1. The issue arises from a lack of proper authorization on the 'elementinvader_addons_for_elementor_forms_send_form' action, allowing unauthenticated users to send arbitrary emails to any address. Exploitation involves submitting a contact form with fake data and intercepting the request to add specific parameters, including email details and a token that is only valid for one use.

Impact

Exploitation of this vulnerability allows for unauthorized email sending, which could be misused for phishing or spam.

Reproduction

To reproduce this vulnerability, first ensure the ElementInvader Addons for Elementor WordPress plugin is installed and active on a WordPress site. Then, open a page with the Eli Contact Form embedded using the Elementor Builder. Submit the form with dummy data to trigger the 'elementinvader_addons_for_elementor_forms_send_form' action. Intercept the request and add the necessary parameters, such as 'mail_data_subject', 'mail_data_to_email', 'mail_data_from_name', 'mail_data_from_email', 'usermail', and 'message_body'. Forward the modified request to send the email. The 'eli_token' parameter must be refreshed with each request, as it is tied to the request's IP address and User Agent.

Remediation

Users are advised to update the ElementInvader Addons for Elementor WordPress plugin to version 1.4.1 or later.

Added: Nov 5, 2025, 6:22 AM
Updated: Nov 5, 2025, 6:22 AM

Vulnerability Rating

Custom Algorithm
spread
1.6
impact
0.6
exploitability
9.7
remediation
7.7
relevance
0.9
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.