CVE · Medium

CVE-2021-4446 — Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.6.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-4446 Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 4.6.5 Missing Authorization Medium 4.3 < 4.6.5 4.6.5 2021-05-05

CVE-2021-4446

The Essential Addons for Elementor plugin before version 4.6.5 contains an authorization bypass vulnerability affecting authenticated users with low-privilege accounts like subscribers. The flaw stems from absent capability verification and exposed nonces, allowing attackers to execute unauthorized actions including modifying plugin settings and deploying arbitrary plugins despite lacking proper permissions.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.