CVE-2023-4723
Elementor Addon Elements <= 1.12.7 - Missing Authorization to Sensitive Information Exposure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the ajax_eae_post_data function. This can allow unauthenticated attackers to extract sensitive data including post/page ids and titles including those of with pending/draft/future/private status.
El complemento Elementor Addon Elements para WordPress es vulnerable a la Exposición de Información Confidencial en versiones hasta la 1.12.7 incluida a través de la función ajax_eae_post_data. Esto puede permitir a atacantes no autenticados extraer datos confidenciales, incluidos los ID y títulos de publicaciones/páginas, incluidos aquellos con estado pendiente/borrador/futuro/privado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-01 CVE Reserved
- 2023-11-15 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Webtechstreet Search vendor "Webtechstreet" | Elementor Addon Elements Search vendor "Webtechstreet" for product "Elementor Addon Elements" | <= 1.12.7 Search vendor "Webtechstreet" for product "Elementor Addon Elements" and version " <= 1.12.7" | wordpress |
Affected
|