What the vulnerability does
01Description
Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.
Explanation of Vulnerability in Simple Terms
Essential Addons for Elementor versions up to 5.8.8 contain a privilege management flaw that allows authenticated users with low-level permissions to perform actions reserved for higher-privilege roles. An attacker with a basic user account can read sensitive data, modify site content, or disrupt service without requiring additional user interaction.
What an attacker can do
Read sensitive data, modify site content, or disrupt service using a low-privilege user account.
Potential impact on your site
Compromised user accounts can escalate their capabilities beyond intended permissions, risking data theft and unauthorized content changes.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities