CVE-2023-3124 HIGH

CVE-2023-3124: Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option

Vendor Https://Elementor.com/
Product Elementor Website Builder Pro
Weakness CWE-862 · Missing authorization
Published June 7, 2023
Last update April 8, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

Explanation of Vulnerability in Simple Terms

02Summary

Elementor Website Builder Pro versions up to 3.11.6 lack proper authorization checks, allowing authenticated users with low privileges to perform actions restricted to higher-privilege roles. An attacker with a basic user account can read, modify, or delete sensitive site data and functionality. Update to a version newer than 3.11.6 to resolve this issue.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete site data and functionality without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users can access and alter critical site content, settings, and data.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege authenticated account on the site.

Key dates

06Disclosure timeline

June 7, 2023 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE