What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Piotnet Piotnet Addons For Elementor Pro.This issue affects Piotnet Addons For Elementor Pro: from n/a through 7.1.17.
Explanation of Vulnerability in Simple Terms
Piotnet Addons For Elementor Pro versions up to 7.1.17 contain a cross-site request forgery vulnerability. An attacker can craft a malicious link or page that, when visited by a logged-in site administrator, performs unwanted actions on the site without the admin's knowledge or consent. The vulnerability requires user interaction and does not expose sensitive data, but can modify site content or settings.
What an attacker can do
Trick a logged-in admin into performing unwanted actions (modify settings, create content, change configurations) via a malicious link or page.
Potential impact on your site
An attacker can modify your site's content, settings, or user accounts if an admin visits a malicious link while logged in.
Conditions required to exploit
A logged-in site administrator must visit a malicious link or page controlled by the attacker.
Key dates
External resources
Related vulnerabilities