Layouts for Elementor <= 1.7 - Missing Authorization to Unauthenticated Arbitrary File Upload

2024-03-29 00:00
Abdi Pranata

Strategic Overview

Status
Patched in 1.8
Affected PluginLayouts for Elementor
Affected Version<= 1.7
CVSS10.0Critical
CVECVE-2024-30533
View all Layouts for Elementor vulnerabilities

Vulnerability Overview

The Layouts for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the handle_import() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to upload arbitrary files that can be used to achieve remote code execution.

Technical Analysis

REMEDIATION: Update to version 1.8, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C