Elementor <= 3.13.2 Authenticated(Contributor+) Arbitrary Post Type Creation via save_item

2023-05-22 00:00
Rafie Muhammad

Strategic Overview

Vulnerability Overview

The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validation in the template "save_item" function in versions up to, and including, 3.13.3. This allows authenticated attackers, with contributor-level permissions or above, to create templates with an arbitrary post type, potentially allowing the exploitation of other plugins that depend on custom post types.

Technical Analysis

REMEDIATION: Update to version 3.13.3, or a newer patched version --- IDENTIFIER: CWE-1229 (Creation of Emergent Resource) The product manages resources or behaves in a way that indirectly creates a new, distinct resource that can be used by attackers in violation of the intended policy.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C