CVE · High

CVE-2024-37455 — Ultimate Addons for Elementor [ultimate-elementor] < 1.36.32

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-37455 Ultimate Addons for Elementor [ultimate-elementor] < 1.36.32 Improper Privilege Management High 8.8 < 1.36.32 1.36.32 2024-07-01

CVE-2024-37455

The Ultimate Addons for Elementor plugin for WordPress contains a privilege escalation flaw affecting versions 1.36.31 and earlier. Attackers with authenticated contributor-level or higher access can exploit this vulnerability to elevate their privileges to administrator status on affected WordPress installations. The issue was resolved in version 1.36.32 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.