CVE Database /
CVE-2023-39993
CVE · Medium
CVE-2023-39993 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 2.9.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-39993
|
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 2.9.2 |
Missing Authorization |
Medium
4.3
|
< 2.9.2
|
2.9.2 |
2023-08-23 |
—
|
CVE-2023-39993
The ElementsKit Elementor Addons plugin versions before 2.9.2 contains a broken access control vulnerability that allows unauthorized users to perform actions reserved for privileged accounts due to missing authorization and authentication checks. Researcher Rafie Muhammad identified this flaw, which stems from insufficient nonce token validation in affected functions. As of the advisory date, the vendor acknowledged the issue but no patched version had been released to address the vulnerability.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings