What the vulnerability does
01Description
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
Explanation of Vulnerability in Simple Terms
Essential Addons for Elementor versions 5.4.0 through 5.7.1 contain an authentication bypass vulnerability. An attacker can gain unauthorized access to the plugin's functionality without providing valid credentials. This affects all installations of the affected versions. Update to a version newer than 5.7.1 to resolve the issue.
What an attacker can do
Bypass authentication and gain unauthorized access to plugin features without valid credentials.
Potential impact on your site
Attackers can access restricted plugin features and potentially modify site content or settings without logging in.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities