Korean
<< Back
VID 210244
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The WordPress Essential Addons for Elementor Plugin installed on the remote host is affected by a privilege escalation vulnerability due to improper authentication.

* References:
https://patchstack.com/articles/critical-privilege-escalation-in-essential-addons-for-elementor-plugin-affecting-1-million-sites
https://wordpress.org/plugins/essential-addons-for-elementor-lite/

* Platforms Affected:
WordPress prior to 5.7.2
Any operating system Any version
Recommendation Upgrade to the version (5.7.2 or later) fixed this vulnerability, available from the WordPress Download Web page at http://wordpress.org/download/
Related URL CVE-2023-32243 (CVE)
Related URL (SecurityFocus)
Related URL (ISS)