What the vulnerability does
01Description
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.
Explanation of Vulnerability in Simple Terms
Element Pack Elementor Addons versions up to 8.7.13 contain an authentication bypass vulnerability that allows attackers to spoof credentials and modify site content without valid authentication. The flaw stems from insufficient verification of user identity during requests. No user interaction or special privileges are required to exploit this issue.
What an attacker can do
Modify site content and settings without providing valid login credentials.
Potential impact on your site
Unauthorized users can alter pages, posts, and plugin settings without logging in.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities