CVE · High

CVE-2023-48760 — JetElements For Elementor [jet-elements] < 2.6.13.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-48760 JetElements For Elementor [jet-elements] < 2.6.13.1 Missing Authorization High 8.2 < 2.6.13.1 2.6.13.1 2023-11-28

CVE-2023-48760

The JetElements For Elementor plugin before version 2.6.13.1 contains a broken access control flaw that allows unauthenticated or low-privilege users to perform actions that should be restricted to higher-privilege accounts. The vulnerability stems from missing authorization and authentication checks in a plugin function. This issue was discovered by Rafie Muhammad and addressed in version 2.6.13.1 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.