CVE-2023-33922

Elementor <= 3.13.2 Authenticated(Contributor+) Arbitrary Post Type Creation via save_item

2023-05-22 00:00
Rafie Muhammad

Strategic Overview

Status
Patched in 3.13.3
Affected Version
< 3.13.3
CVSS
5.4Medium
Weakness type
CWE-1229 · Creation of Emergent Resource
CVE
CVE-2023-33922
View all Elementor Website Builder – more than just a page builder vulnerabilities

At a glance

CVE-2023-33922 is a medium-severity Creation of Emergent Resource vulnerability in the Elementor Website Builder WordPress plugin, affecting versions < 3.13.3. It carries a CVSS score of 5.4 (reachable over the network; low attack complexity). Exploitation requires an authenticated account at Contributor level or above. The issue is fixed in version 3.13.3; sites on affected versions should update now. Disclosed May 2023, reported by Rafie Muhammad.

Vulnerability Overview

The Elementor plugin for WordPress is vulnerable to the creation of emergent resources due to insufficient input validation in the template "save_item" function in versions up to, and including, 3.13.3. This allows authenticated attackers, with contributor-level permissions or above, to create templates with an arbitrary post type, potentially allowing the exploitation of other plugins that depend on custom post types.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user.

CWE-1229: Creation of Emergent Resource

The product manages resources or behaves in a way that indirectly creates a new, distinct resource that can be used by attackers in violation of the intended policy.

Remediation

Update to version 3.13.3, or a newer patched version

How does WordSec protect against this?

The fix is the thing that ends this: Elementor Website Builder 3.13.3 closes this, and updating the plugin is the step that ends it.

  • Alerts

External References

Related records

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C