The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins.
References
Configurations
Configuration 1 (hide)
|
History
10 Jan 2025, 14:46
Type | Values Removed | Values Added |
---|---|---|
First Time |
Wpdeveloper
Wpdeveloper essential Addons For Elementor |
|
CPE | cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:* | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2526471%40essential-addons-for-elementor-lite&new=2526471%40essential-addons-for-elementor-lite&sfp_email=&sfph_mail= - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/283fb581-8b61-4008-a5c4-2e1490fab33e?source=cve - Third Party Advisory |
16 Oct 2024, 16:38
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
16 Oct 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-16 07:15
Updated : 2025-01-10 14:46
NVD link : CVE-2021-4446
Mitre link : CVE-2021-4446
CVE.ORG link : CVE-2021-4446
JSON object : View
Products Affected
wpdeveloper
- essential_addons_for_elementor
CWE
CWE-862
Missing Authorization