Impact
A missing authorization flaw exists in WPDeveloper Essential Addons for Elementor that allows exploitation of incorrectly configured access control security levels. The vulnerability permits a user to access privileged functions of the plugin without proper authorization.
Affected Systems
WordPress sites that have installed WPDeveloper’s Essential Addons for Elementor plugin, any release up to and including version 6.5.5. No specific build numbers are indicated, so all versions in this range are considered affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely via interaction with the plugin’s administrative interface, where a user with a lower than required role may gain elevated privileges. No additional exploitation conditions are mentioned in the CVE data.
OpenCVE Enrichment