Description
Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.33.0.
Published: 2025-12-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in Elementor's Website Builder plugin, allowing attackers to exploit incorrectly configured access control levels. This flaw provides unauthorized access to functions that should be protected, potentially enabling the creation, editing, or deletion of content without proper permission.

Affected Systems

WordPress sites that employ the Elementor Website Builder plugin up to and including version 3.33.0 are affected. All users who interact with the plugin via the web interface are potentially vulnerable, as the issue applies regardless of the user’s role.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Although the description does not detail the exact attack vector, the likely exploitation path involves a web request to the plugin’s exposed endpoints, implying that any site visitor could potentially trigger the unauthorized actions. Prompt patching is recommended to mitigate this risk.

Generated by OpenCVE AI on April 29, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Elementor plugin to version 3.33.1 or later.
  • Verify the plugin settings to enforce appropriate access controls and disable any unused features.
  • Review WordPress user role permissions to ensure that only authorized roles retain the necessary capabilities for interacting with Elementor.

Generated by OpenCVE AI on April 29, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Elementor
Elementor website Builder
Wordpress
Wordpress wordpress
Vendors & Products Elementor
Elementor website Builder
Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Tue, 09 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.33.0.
Title WordPress Elementor Website Builder plugin <= 3.33.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Elementor Website Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:22.112Z

Reserved: 2025-12-09T12:21:39.680Z

Link: CVE-2025-67588

cve-icon Vulnrichment

Updated: 2025-12-09T20:58:21.631Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:36.800

Modified: 2026-04-27T18:16:45.100

Link: CVE-2025-67588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T19:30:18Z

Weaknesses