What the vulnerability does
01Description
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.31.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Brainstorm Force Ultimate Addons for Elementor allows Privilege Escalation.This issue affects Ultimate Addons for Elementor: from n/a through 1.36.31.
Explanation of Vulnerability in Simple Terms
Ultimate Addons for Elementor versions up to 1.36.31 contain a privilege management flaw that allows authenticated users with low-level permissions to perform actions reserved for administrators. An attacker with a basic user account can read sensitive data, modify site content, or disrupt service without requiring additional user interaction. Update to a version newer than 1.36.31 to resolve this issue.
What an attacker can do
Read sensitive data, modify site content, or disrupt service with a low-privilege user account.
Potential impact on your site
Any registered user can escalate their privileges and perform admin-level actions on your site.
Conditions required to exploit
Attacker must have a valid user account with low-level permissions on the site.
Key dates
External resources
Related vulnerabilities