Zita Elementor Site Library <= 1.6.2 - Missing Authorization to Page Creation and Options Modification

2024-06-24 00:00
Lucio Sá

Strategic Overview

Status
Patched in 1.6.3
Affected Version<= 1.6.2
CVSS4.3Medium
CVECVE-2024-3249
View all Zita Site Library for Elementor vulnerabilities

Vulnerability Overview

The Zita Elementor Site Library plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_xml_data, xml_data_import, import_option_data, import_widgets, and import_customizer_settings functions in all versions up to, and including, 1.6.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to create pages, update certain options, including WooCommerce page titles and Elementor settings, import widgets, and update the plugin's customizer settings and the WordPress custom CSS. NOTE: This vulnerability was partially fixed in version 1.6.2.

Technical Analysis

REMEDIATION: Update to version 1.6.3, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C