CVE · Medium

CVE-2023-35050 — Elementor Pro [elementor-pro] < 3.13.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-35050 Elementor Pro [elementor-pro] < 3.13.1 Missing Authorization Medium 5.4 < 3.13.1 3.13.1 2023-06-20

CVE-2023-35050

Elementor Pro versions up to 3.13.0 contain a capability check vulnerability that permits authenticated users with subscriber-level permissions to execute unauthorized operations, including modifying screenshots and accessing sensitive data. The flaw stems from missing permission validation on multiple functions within the plugin. This vulnerability could allow lower-privileged users to alter website content, view restricted information, or delete data they should not have access to. The issue was patched in version 3.13.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.