CVE · High

CVE-2023-3124 — Elementor Pro [elementor-pro] < 3.11.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3124 Elementor Pro [elementor-pro] < 3.11.7 Missing Authorization High 8.8 < 3.11.7 3.11.7 2023-03-28

CVE-2023-3124

Elementor Pro through version 3.11.6 contains a vulnerability in the update_page_option function that fails to properly verify user permissions before allowing modifications. Authenticated users with basic subscriber access can exploit this weakness to alter any site options without authorization. The flaw creates a path for privilege escalation as attackers can modify critical configuration settings intended only for administrators. The vulnerability was resolved in version 3.11.7.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.