CVE-2023-0329

CVE-2023-0329: Elementor Website Builder < 3.12.2 - Admin+ SQLi

Vendor Unknown
Product Elementor Website Builder
Published May 30, 2023
Last update April 23, 2025

CVSS base score

What the vulnerability does

01Description

The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.

Key dates

02Disclosure timeline

May 30, 2023 CVE published
April 23, 2025 Record updated