What the vulnerability does
01Description
Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
Explanation of Vulnerability in Simple Terms
JetElements For Elementor versions up to 2.6.13 lack proper authorization checks on certain functionality. An unauthenticated attacker can read sensitive data by making direct requests to the plugin. The vulnerability does not allow modification or deletion of data, only unauthorized access to information. Update to a version newer than 2.6.13.
What an attacker can do
Read sensitive data without authentication by sending direct requests to the plugin.
Potential impact on your site
Sensitive information exposed to anyone on the internet without needing a site account.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities