WP Clinic
Log in Sign up

CVE · High

CVE-2023-48759 — JetElements For Elementor [jet-elements] < 2.6.13.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-48759 JetElements For Elementor [jet-elements] < 2.6.13.1 Missing Authorization High 7.5 < 2.6.13.1 2.6.13.1 2023-11-28

CVE-2023-48759

Update the WordPress JetElements For Elementor plugin to the latest available version (at least 2.6.13.1). Rafie Muhammad (Patchstack) discovered and reported this Arbitrary File Download vulnerability in WordPress JetElements For Elementor Plugin. This could allow a malicious actor to download any file from your website. This includes but is not limited to files that contain login credentials or backup files. This vulnerability has been fixed in version 2.6.13.1.

Source: Patchstack

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.