CVE-2023-41955
WordPress Essential Addons for Elementor plugin <= 5.8.8 - Contributor+ Privilege Escalation vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Privilege Management vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation.This issue affects Essential Addons for Elementor: from n/a through 5.8.8.
Una vulnerabilidad de gestiĆ³n de privilegios incorrecta en WPDeveloper Essential Addons para Elementor permite la escalada de privilegios. Este problema afecta a Essential Addons para Elementor: desde n/a hasta 5.8.8.
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 5.8.8 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user. Note that this is difficult to exploit without publishing capabilities and appears to be a regression, as an identical issue was patched in version 4.6.5.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-09-06 CVE Reserved
- 2023-09-14 CVE Published
- 2024-05-17 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
- CWE-862: Missing Authorization
CAPEC
- CAPEC-233: Privilege Escalation
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Essential Addons For Elementor Lite Search vendor "Essential Addons For Elementor Lite" | Essential Addons For Elementor Lite Search vendor "Essential Addons For Elementor Lite" for product "Essential Addons For Elementor Lite" | >= 0.0.0 <= 5.8.8 Search vendor "Essential Addons For Elementor Lite" for product "Essential Addons For Elementor Lite" and version " >= 0.0.0 <= 5.8.8" | en |
Affected
|