CVE · Medium

CVE-2023-39993 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 2.9.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-39993 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 2.9.2 Missing Authorization Medium 4.3 < 2.9.2 2.9.2 2023-08-23

CVE-2023-39993

The ElementsKit Elementor Addons plugin versions before 2.9.2 contains a broken access control vulnerability that allows unauthorized users to perform actions reserved for privileged accounts due to missing authorization and authentication checks. Researcher Rafie Muhammad identified this flaw, which stems from insufficient nonce token validation in affected functions. As of the advisory date, the vendor acknowledged the issue but no patched version had been released to address the vulnerability.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.