The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins. | |
Title | Essential Addons for Elementor <= 4.6.4 - Missing Authorization | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-10-16T06:43:25.787Z
Updated: 2024-10-16T15:34:14.629Z
Reserved: 2024-10-15T18:28:06.856Z
Link: CVE-2021-4446
Vulnrichment
Updated: 2024-10-16T15:33:59.590Z
NVD
Status : Awaiting Analysis
Published: 2024-10-16T07:15:10.447
Modified: 2024-10-16T16:38:14.557
Link: CVE-2021-4446
Redhat
No data.