Elementor <= 3.13.2 Authenticated(Contributor+) Arbitrary Post Type Creation via save_item
Strategic Overview
< 3.13.3CVE-2023-33922Vulnerability Overview
The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validation in the template "save_item" function in versions up to, and including, 3.13.3. This allows authenticated attackers, with contributor-level permissions or above, to create templates with an arbitrary post type, potentially allowing the exploitation of other plugins that depend on custom post types.
Technical Analysis
REMEDIATION: Update to version 3.13.3, or a newer patched version --- IDENTIFIER: CWE-1229 (Creation of Emergent Resource) The product manages resources or behaves in a way that indirectly creates a new, distinct resource that can be used by attackers in violation of the intended policy.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C