Impact
A missing authorization check in the King Addons for Elementor plugin enables users to perform actions outside their permitted scope. The flaw can let an attacker modify or delete content, create sections, or otherwise manipulate the website without proper privilege. This vulnerability is classified as a broken access control flaw.
Affected Systems
The vulnerability affects the King Addons for Elementor plugin from KingAddons.com, with all releases up to and including version 24.12.58. WordPress sites running any of these versions are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning there are no known active exploits yet. The likely attack vector is inferred to be a logged-in user who can gain elevated privileges within the plugin’s administrative interface.
OpenCVE Enrichment
EUVD