CVE-2023-47827
The Events Addon for Elementor plugin through version 2.1.2 contains multiple AJAX functions that lack proper capability verification, allowing anyone to modify plugin settings without authentication. The vulnerable functions include naevents_bw_settings_save_func(), naevents_bw_toggle_submit_func(), naevents_pro_settings_save_func(), naevents_pro_toggle_submit_func(), and naevents_uw_settings_save_func(), each exposed through nopriv AJAX actions. An unauthenticated attacker could exploit this flaw to change the plugin's configuration. The vulnerability was fixed in version 2.1.3.
Based on public CVE data (MITRE/NVD).