CVE

CVE-2026-2386 — The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce < 6.4.8 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type'

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-2386 The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce < 6.4.8 - Incorrect Authorization to Authenticated (Author+) Arbitrary Draft Post Creation via 'post_type' Unknown < 6.4.8 6.4.8

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.