Elementor Website Builder <= 2.9.5 - Authorization Bypass

2020-03-31 00:00
Jerome Bruandet

Strategic Overview

Vulnerability Overview

Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.

Technical Analysis

REMEDIATION: Update to version 2.9.6, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C