Elementor <= 3.13.2 Authenticated(Contributor+) Arbitrary Post Type Creation via save_item
Strategic Overview
- Status
- Patched in 3.13.3
- Affected Plugin
- Elementor Website Builder – more than just a page builder
- Affected Version
< 3.13.3- CVSS
- 5.4Medium
- Weakness type
- CWE-1229 · Creation of Emergent Resource
- CVE
CVE-2023-33922
At a glance
CVE-2023-33922 is a medium-severity Creation of Emergent Resource vulnerability in the Elementor Website Builder WordPress plugin, affecting versions < 3.13.3. It carries a CVSS score of 5.4 (reachable over the network; low attack complexity). Exploitation requires an authenticated account at Contributor level or above. The issue is fixed in version 3.13.3; sites on affected versions should update now. Disclosed May 2023, reported by Rafie Muhammad.
Vulnerability Overview
The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validation in the template "save_item" function in versions up to, and including, 3.13.3. This allows authenticated attackers, with contributor-level permissions or above, to create templates with an arbitrary post type, potentially allowing the exploitation of other plugins that depend on custom post types.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.
CWE-1229: Creation of Emergent Resource
The product manages resources or behaves in a way that indirectly creates a new, distinct resource that can be used by attackers in violation of the intended policy.
Remediation
Update to version 3.13.3, or a newer patched version
How does WordSec protect against this?
The fix is the thing that ends this: Elementor Website Builder 3.13.3 closes this, and updating the plugin is the step that ends it.
- Alerts
External References
Related records
Other vulnerabilities in Elementor Website Builder – more than just a page builder
- 8.8CVE-2024-24934: Elementor Arbitrary File Deletion and PHAR
CVE-2024-24934 - 8.8CVE-2023-48777: Elementor <= 3.18.1 Arbitrary File Upload to RCE
CVE-2023-48777 - 8.8CVE-2022-1329: Elementor Website Builder 3.6.0 - 3.6.2 RCE
CVE-2022-1329 - 8.8CVE-2020-7055: Elementor Website Builder Arbitrary File Upload
CVE-2020-7055 - 8.8CVE-2017-18596: Elementor Website Builder Missing Authorization
CVE-2017-18596 - 7.2CVE-2020-7109: Elementor Website Builder <= 2.8.3 Cross-Site Scripting
CVE-2020-7109 - 6.6CVE-2023-0329: Elementor <= 3.12.1 SQL Injection
CVE-2023-0329 - 6.5CVE-2023-47504: Elementor Website Builder Arbitrary Attachment Read
CVE-2023-47504
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C