Access violation vulnerability in ElementInvader Addons for Elementor 1.4.0

A popular plugin for WordPress called ElementInvader Addons for Elementor has a security issue where anyone can send emails without being logged in. This affects all versions up to 1.4.0. The problem is with a part of the plugin called ‘elementinvader_addons_for_elementor_forms_send_form’ that lets users enter the email content, as well as the sender and recipient email addresses. Because of this, hackers can send any emails they want from the website without needing to log in.

Detected in:

ElementInvader Addons for Elementor fixed vulnerable versions: >= * <= 1.4.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.