CVE · High

CVE-2023-48759 — JetElements For Elementor [jet-elements] < 2.6.13.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-48759 JetElements For Elementor [jet-elements] < 2.6.13.1 Missing Authorization High 7.5 < 2.6.13.1 2.6.13.1 2023-11-28

CVE-2023-48759

The JetElements For Elementor plugin before version 2.6.13.1 contains an arbitrary file download flaw that could allow attackers to retrieve sensitive files from an affected website, such as those containing authentication credentials or system backups. Researcher Rafie Muhammad discovered this vulnerability and reported it through Patchstack. The security issue was addressed in version 2.6.13.1 and users should upgrade to this version or later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.