What the vulnerability does
01Description
Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0.
Explanation of Vulnerability in Simple Terms
Elements Kit for Elementor is missing authorization checks on certain administrative functions. A logged-in user with low privileges can modify site settings or data they should not have access to. The vulnerability affects versions up to 2.9.0. Update to a version newer than 2.9.0 to resolve this issue.
What an attacker can do
A low-privilege user can modify site settings or data without proper authorization.
Potential impact on your site
Unauthorized users may alter site configuration, content, or settings depending on which functions lack authorization checks.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities