What the vulnerability does
01Description
The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins.
Explanation of Vulnerability in Simple Terms
02Summary
Essential Addons for Elementor versions up to 4.6.4 lack proper authorization checks, allowing authenticated users to read, modify, or delete data they should not have access to. An attacker with a low-privilege account can exploit this to access sensitive information or alter site content. Update to a version newer than 4.6.4 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read, modify, or delete data belonging to other users or restricted areas of the site.
Potential impact on your site
04Site Impact
Unauthorized users can access or alter sensitive data, potentially compromising site integrity and user privacy.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site; no user interaction required.
Key dates
06Disclosure timeline
October 16, 2024
CVE published
April 8, 2026
Record updated