QID 150686

Date Published: 2023-05-25

QID 150686: WordPress Essential Addons for Elementor Plugin: Improper Authentication Vulnerability (CVE-2023-32243)

Essential Addons for Elementor is a powerful plugin that enhances the functionality of the Elementor page builder.

This plugin suffers from an unauthenticated privilege escalation vulnerability, allowing any unauthenticated user to escalate their privileges to that of any user on the WordPress site.

Affected versions:
Essential Addons for Elementor Plugin from 5.4.0 to 5.7.1

QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a plugin running on the target application.

The vulnerability could allow a malicious actor to escalate their low-privileged account to an account with higher privileges. Once elevated privileges are obtained, the attacker can gain full control of the website.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to upgrade to Essential Addons for Elementor 5.7.2 or later version to remediate this vulnerability.
    Vendor References

    CVEs related to QID 150686

    Software Advisories
    Advisory ID Software Component Link
    Essential Addons for Elementor URL Logo wordpress.org/plugins/essential-addons-for-elementor-lite/