Impact
A missing authorization check in the ElementsKit Elementor addons Lite plugin allows an attacker to perform actions that should be restricted to privileged users. Exploitation can lead to unauthorized manipulation of plugin settings or content insertion within the WordPress site. The weakness resides in CWE‑862, a broken access control vulnerability.
Affected Systems
Wpmet’s ElementsKit Elementor addons Lite plugin is affected, specifically all releases up to and including version 3.9.6.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, while the EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. Likely attack conditions involve an authenticated user exploiting misconfigured access levels; the vulnerability can be leveraged during normal user sessions without additional prerequisites.
OpenCVE Enrichment