Impact
Element Invader – Template Kits for Elementor contains a missing authorization check that permits incorrectly configured access control, allowing unintended users to create or modify template kits without proper role verification. This results in unauthorized content changes and falls under the CWE-862 category of Authorization Bypass.
Affected Systems
The vulnerability affects all installations of Element Invader – Template Kits for Elementor from earliest release up to and including version 1.2.4. Hosts running WordPress with this plugin should verify their installed version and patch if needed.
Risk and Exploitability
The CVSS score is 4.3, indicating moderate severity. The EPSS value is below 1%, showing a low likelihood of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Likely attack vectors involve authenticated or partially privileged users who can access the plugin’s administration UI; the lack of a clear client‑side exploitation path makes remote exploitation less likely, but an attacker who can get in via other means could abuse the plugin to inject or alter templates.
OpenCVE Enrichment