Impact
The vulnerability is a Addons for Elementor plugin that allows an attacker to perform privileged actions. An attacker who can access the plugin endpoints can change site content or modify plugin settings that should be restricted to administrators, effectively abusing administrative privileges on the WordPress site.
Affected Systems
All releases of the Pixar Labs Master Addons for Elementor from the earliest available version through 3.2.2 are affected. Versions 3.2.3 and later contain the necessary fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that the likelihood of exploitation is low but not zero. The vulnerability is not listed in the CISA KEV catalog, and there is no known exploit published. An attacker could exploit the flaw by sending specially crafted requests to the plugin’s endpoints or they have authentication to reach the area. The risk is moderate to high for sites that expose Elementor addon functionality to users who are not administrators.
OpenCVE Enrichment