Impact
The ElementsKit Elementor addons Lite plugin for WordPress contains a missing authorization check that allows attackers to exploit incorrectly configured access control settings. This flaw permits unauthorized individuals to gain elevated privileges within the plugin, potentially exposing or altering sensitive site data. The vulnerability is categorized as broken access control (CWE-862).
Affected Systems
Affected systems include the Wpmet ElementsKit Elementor addons Lite plugin for WordPress, with all releases up to and including version 3.9.6. Organizations running any of these versions are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. No EPSS value is available, so the current probability of exploitation is unknown, and the vulnerability has not been listed in CISA’s KEV catalog. The flaw likely requires the attacker to identify or craft a request that bypasses access checks, which may be possible by manipulating URLs, submitting malformed requests, or exercising API endpoints. Because the attack vector is not explicitly specified, it is inferred that an attacker with some level of access to the WordPress site could exploit the missing authorization, but it could also be leveraged remotely if the vulnerable endpoint is exposed.
OpenCVE Enrichment