What the vulnerability does
01Description
Missing Authorization vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon Elements: from n/a through <= 1.13.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in WPVibes Elementor Addon Elements addon-elements-for-elementor-page-builder.This issue affects Elementor Addon Elements: from n/a through <= 1.13.6.
Explanation of Vulnerability in Simple Terms
The Elementor Addon Elements plugin for WordPress does not properly check user permissions before allowing certain actions. A logged-in user with low privileges can perform administrative operations they should not have access to, potentially disrupting site availability. Update to a version newer than 1.13.6.
What an attacker can do
A low-privilege logged-in user can perform administrative actions and disrupt site availability.
Potential impact on your site
Unauthorized users can perform admin-level operations, risking site downtime or unwanted configuration changes.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities