CVE-2024-10663 MEDIUM

CVE-2024-10663: Eleblog – Elementor Blog And Magazine Addons <= 1.8 - Missing Authorization to Authenticated (Subscriber+) Deactivation Submission

Vendor Smarettheme
Product Eleblog – Elementor Blog And Magazine Addons
Weakness CWE-862 · Missing authorization
Published December 4, 2024
Last update April 8, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the goodbye_form_callback() function in all versions up to, and including, 1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit a deactivation reason.

Explanation of Vulnerability in Simple Terms

02Summary

Eleblog – Elementor Blog And Magazine Addons versions 1.8 and earlier lack proper authorization checks on certain functions. A logged-in user with low privileges can modify content or settings they should not have access to. The vulnerability requires an active user account but no special interaction from the victim.

What an attacker can do

03Attacker Capabilities

Modify or change content or settings without proper permission.

Potential impact on your site

04Site Impact

Unauthorized users can alter blog posts, magazine content, or plugin settings.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site.

Key dates

06Disclosure timeline

December 4, 2024 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE