Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.65 - Missing Authorization

2023-06-20 00:00
Rafie Muhammad

Strategic Overview

Status
Patched in 1.5.66
Affected Version<= 1.5.65
CVSS6.3Medium
CVECVE-2023-31080
View all Unlimited Elements For Elementor vulnerabilities

Vulnerability Overview

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the extensive functions throughout the plugin in versions up to, and including, 1.5.65. This makes it possible for authenticated attackers, with contributor-level access and above, to perform a plethora of unauthorized actions such as updating/ deleting/modfying addons and modifying various settings.

Technical Analysis

REMEDIATION: Update to version 1.5.66, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C