What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.
Explanation of Vulnerability in Simple Terms
Essential Addons for Elementor versions up to 6.8.0 contain an authentication bypass vulnerability that allows attackers to spoof credentials and modify site content without valid authentication. The vulnerability requires no user interaction and can be exploited remotely over the network. Site administrators should update to a version newer than 6.8.0 immediately.
What an attacker can do
Modify site content without providing valid login credentials.
Potential impact on your site
Attackers can alter pages, posts, or plugin settings without logging in, potentially defacing or compromising your site.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities