QID 150686
Date Published: 2023-05-25
QID 150686: WordPress Essential Addons for Elementor Plugin: Improper Authentication Vulnerability (CVE-2023-32243)
Essential Addons for Elementor is a powerful plugin that enhances the functionality of the Elementor page builder.
This plugin suffers from an unauthenticated privilege escalation vulnerability, allowing any unauthenticated user to escalate their privileges to that of any user on the WordPress site.
Affected versions:
Essential Addons for Elementor Plugin from 5.4.0 to 5.7.1
QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a plugin running on the target application.
The vulnerability could allow a malicious actor to escalate their low-privileged account to an account with higher privileges. Once elevated privileges are obtained, the attacker can gain full control of the website.
Solution
Customers are advised to upgrade to Essential Addons for Elementor 5.7.2 or later version to remediate this vulnerability.
Vendor References
CVEs related to QID 150686
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Essential Addons for Elementor |
|