WP Clinic
Entrar Registrarse

CVE · High

CVE-2023-31080 — Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2023-31080 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66 Falta de control de autorización Alta 8,3 < 1.5.66 1.5.66 2023-06-20

CVE-2023-31080

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the extensive functions throughout the plugin in versions up to, and including, 1.5.65. This makes it possible for authenticated attackers, with contributor-level access and above, to perform a plethora of unauthorized actions such as updating/ deleting/modfying addons and modifying various settings.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.