The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The issue was partially patched in version 1.5.66 and fully patched in 1.5.67. CVE-2023-31231 appears to be a duplicate of this issue.
History

Mon, 14 Oct 2024 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Unlimited-elements unlimited Elements For Elementor
CPEs cpe:2.3:a:unlimited-elements:unlimited_elements_for_elementor_\(free_widgets\,_addons\,_templates\):*:*:*:*:*:wordpress:*:* cpe:2.3:a:unlimited-elements:unlimited_elements_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Unlimited-elements unlimited Elements For Elementor \(free Widgets\, Addons\, Templates\)
Unlimited-elements unlimited Elements For Elementor

Fri, 09 Aug 2024 17:45:00 +0000

Type Values Removed Values Added
Description The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The issue was partially patched in version 1.5.66 and fully patched in 1.5.67 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) for WordPress is vulnerable to arbitrary file uploads due to missing file type validation of files in the file manager functionality in versions up to, and including, 1.5.66 . This makes it possible for authenticated attackers, with contributor-level permissions and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. The issue was partially patched in version 1.5.66 and fully patched in 1.5.67. CVE-2023-31231 appears to be a duplicate of this issue.
Title Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.66 - Authenticated (Contributor+) Arbitrary File Upload
Weaknesses CWE-434

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2023-06-17T01:48:18.106Z

Updated: 2024-08-29T15:51:41.042Z

Reserved: 2023-06-16T12:36:31.620Z

Link: CVE-2023-3295

cve-icon Vulnrichment

Updated: 2024-08-02T06:48:08.554Z

cve-icon NVD

Status : Modified

Published: 2023-06-17T02:15:08.917

Modified: 2024-11-21T08:16:57.110

Link: CVE-2023-3295

cve-icon Redhat

No data.