Impact
The vulnerability is a missing authorization flaw in the Elementor Website Builder plugin that allows an attacker to bypass normal access controls. Because the plugin does not enforce proper permission checks, a user without sufficient administrative privileges can modify site settings, content, or configuration. This could be used to deface a site, insert malicious content, or otherwise alter site behavior. The weakness is categorized as CWE-862.
Affected Systems
WordPress websites that use the Elementor Website Builder plugin up to and including version 4.1.0 are affected. Sites running earlier releases, or that have patched to 4.1.1 or later, are no longer vulnerable according to the vendor’s guidance.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. No EPSS score is available, so the current predicted exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through plugin endpoints that are reachable by users with non-administrative accounts; this inference is based on the description of missing authorization. No special prerequisites beyond normal user access are described.
OpenCVE Enrichment