Exclusive Addons Elementor <= 2.6.9.1 - Missing Authorization to Post Duplication

2024-04-29 00:00
Khalid

Strategic Overview

Status
Patched in 2.6.9.2
Affected Version<= 2.6.9.1
CVSS5.4Medium
CVECVE-2024-33914
View all Exclusive Addons for Elementor vulnerabilities

Vulnerability Overview

The Exclusive Addons Elementor plugin for WordPress is vulnerable to unauthorized access of datadue to an insufficient capability check on the duplicate_post() function in versions up to, and including, 2.6.9.1. This makes it possible for authenticated attackers, with contributor-level access and above, to duplicate other users posts which can lead to information disclosure for private posts.

Technical Analysis

REMEDIATION: Update to version 2.6.9.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C