CVE-2025-46257
The Element Pack Pro plugin for WordPress has a security flaw that allows malicious individuals to deceive administrators into executing unintended actions, resulting from inadequate validation of authentication tokens in certain functions across all versions up to 7.21.0. This vulnerability can be exploited by an attacker who tricks an administrator into clicking on a link, thereby bypassing normal access controls. The issue arises from the plugin's failure to properly verify the authenticity of requests.
Based on public CVE data (MITRE/NVD).