What the vulnerability does
01Description
The Premium Addons for Elementor plugin for WordPress is vulnerable to Arbitrary Option Updates in versions up to, and including, 4.5.1. This is due to missing capability and nonce checks in the pa_dismiss_admin_notice AJAX action. This makes it possible for authenticated subscriber+ attackers to change arbitrary options with a restricted value of 1 on vulnerable WordPress sites.
Explanation of Vulnerability in Simple Terms
02Summary
Premium Addons for Elementor versions up to 4.5.1 lack proper authorization checks, allowing authenticated users with low privileges to perform actions they should not be able to access. The vulnerability requires user interaction and can affect data confidentiality, integrity, and availability. Site administrators should update to a version newer than 4.5.1.
What an attacker can do
03Attacker Capabilities
A low-privilege authenticated user can perform unauthorized actions affecting site data and functionality.
Potential impact on your site
04Site Impact
Unauthorized users may read, modify, or disrupt site content and functionality if they have any account access.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site and trick a user into clicking a malicious link or visiting a crafted page.
Key dates
06Disclosure timeline
October 16, 2024
CVE published
April 8, 2026
Record updated