Impact
A missing authorization check in the Plus Addons for Elementor Page Builder Lite plugin permits attackers to perform actions on the website without the required permissions. The vulnerability can lead to unauthorized data manipulation or unauthorized usage of plugin functions, which impacts confidentiality and integrity of the site content.
Affected Systems
The affected product is POSIMYTH The Plus Addons for Elementor Page Builder Lite. Versions from the earliest released version up to and including 6.3.13 are vulnerable. Any WordPress installation using these versions of the plugin is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers could craft HTTP requests targeting the plugin’s unsecured endpoints to exploit the missing authorization check. No elevation of privileges appears required; an authenticated user, regardless of, might gain additional capabilities. The vulnerability is a case of authentication bypass (CWE‑862) that can be leveraged when an attacker has access to the plugin’s administrative interfaces.
OpenCVE Enrichment
EUVD