Layouts for Elementor <= 1.7 - Missing Authorization to Unauthenticated Arbitrary File Upload
2024-03-29 00:00
Abdi PranataStrategic Overview
StatusPatched in 1.8
Affected PluginLayouts for Elementor
Affected Version
<= 1.7CVSS10.0Critical
CVE
CVE-2024-30533Vulnerability Overview
The Layouts for Elementor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the handle_import() function in all versions up to, and including, 1.7. This makes it possible for unauthenticated attackers to upload arbitrary files that can be used to achieve remote code execution.
Technical Analysis
REMEDIATION: Update to version 1.8, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C