CVE-2023-3124
Elementor Pro through version 3.11.6 contains a vulnerability in the update_page_option function that fails to properly verify user permissions before allowing modifications. Authenticated users with basic subscriber access can exploit this weakness to alter any site options without authorization. The flaw creates a path for privilege escalation as attackers can modify critical configuration settings intended only for administrators. The vulnerability was resolved in version 3.11.7.
Based on public CVE data (MITRE/NVD).