What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a before 2.10.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in PowerPack Addons for Elementor PowerPack Pro for Elementor.This issue affects PowerPack Pro for Elementor: from n/a before 2.10.8.
Explanation of Vulnerability in Simple Terms
PowerPack Pro for Elementor versions before 2.10.8 are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the site without the admin's knowledge or consent. The vulnerability requires user interaction but can cause data loss or site disruption.
What an attacker can do
Trick a logged-in admin into performing unwanted actions on the site, such as changing settings or deleting content.
Potential impact on your site
Site admins could unknowingly execute harmful actions; attackers could modify plugin settings, delete content, or compromise site configuration.
Conditions required to exploit
Admin must visit a malicious webpage while logged into the WordPress site.
Key dates
External resources
Related vulnerabilities