CVE-2026-28164

WordPress Easy Elementor Addons plugin <= 2.3.7 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.


We have discovered 320 live websites that are affected by CVE-2026-28164.

Run a Free Instant Scan




Affected Software

Product  Easy Elementor Addons
Category Wordpress Plugins
Vulnerable Domains320 live websites (100% of Easy Elementor Addons install base)
Vulnerable Versions
  • from 0 through 2.3.7
Vulnerable Versions Count15 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Aug 20, 2026
  • Updated - Aug 20, 2026

Credits

  • Asim Alshaya | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-28164
United States74 websites



Poland85 websites
Germany16 websites
GB14 websites
Italy11 websites
Netherlands10 websites
Spain9 websites
France8 websites
Turkey6 websites
India5 websites

Website Distribution by TLD

Number of websites using CVE-2026-28164
.com91 websites
.pl80 websites
.org16 websites
.co.uk11 websites
.it10 websites
.es8 websites
.nl8 websites
.de5 websites
.cz4 websites
.ca3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-28164

Top websites that are affected by CVE-2026-28164. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States***,***
**********.com Germany***,***
*************.de Germany***,***
********.com United States*,***,***
********.com United States*,***,***
**********************.**.uk GB*,***,***
**************.pl Poland*,***,***
************.**.uk GB*,***,***
*********.com United States*,***,***
**************.pl Poland*,***,***
See full domain list

FAQ

CVE-2026-28164 is Cross-Site Request Forgery (CSRF) in Easy Elementor Addons
A total of 320 websites have been identified as vulnerable to CVE-2026-28164, based on global website indexing conducted by WebTechSurvey.
The Easy Elementor Addons is affected by the CVE-2026-28164 vulnerability.
Easy Elementor Addons versions up to and including 2.3.7 are vulnerable to CVE-2026-28164.