CVE · High

CVE-2023-41955 — Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.8.9

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-41955 Essential Addons for Elementor – Popular Elementor Templates & Widgets [essential-addons-for-elementor-lite] < 5.8.9 Improper Privilege Management High 8.8 < 5.8.9 5.8.9 2023-09-14

CVE-2023-41955

The Essential Addons for Elementor plugin for WordPress through version 5.8.8 allows privilege escalation because it does not properly control access to registration form creation and custom role assignment functionality within Elementor pages. An attacker with Elementor page builder access can create a registration form that defaults to assigning the administrator role, then use this form to register an account with administrative privileges. The vulnerability requires publishing capabilities to exploit and represents a reintroduction of a flaw that was previously fixed in version 4.6.5.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.