WP Clinic
Log in Sign up

CVE · High

CVE-2023-31080 — Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-31080 Unlimited Elements For Elementor [unlimited-elements-for-elementor] < 1.5.66 Missing Authorization High 8.3 < 1.5.66 1.5.66 2023-06-20

CVE-2023-31080

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on the extensive functions throughout the plugin in versions up to, and including, 1.5.65. This makes it possible for authenticated attackers, with contributor-level access and above, to perform a plethora of unauthorized actions such as updating/ deleting/modfying addons and modifying various settings.

Source: Wordfence

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.