CVE-2026-28164: Hashthemes Easy Elementor Addons

Critical severity, CVSS 9.6. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Elementor Addons: from n/a through 2.3.7.

Affected products

  • Hashthemes Easy Elementor Addons: up to and including 2.3.7

Published 2026-08-20. Last modified 2026-08-24.