What the vulnerability does
01Description
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.
Explanation of Vulnerability in Simple Terms
Ultimate Store Kit Elementor Addons versions up to 3.0.5 lack proper authorization checks on certain functions. An unauthenticated attacker can read and modify sensitive data without permission. The vulnerability requires only network access and no user interaction. Site administrators should update to a version newer than 3.0.5.
What an attacker can do
Read and modify sensitive data without authentication or permission.
Potential impact on your site
Unauthorized users can access and alter site data, potentially compromising store information and customer records.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities