CVE · Medium

CVE-2024-56225 — Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.57

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-56225 Premium Addons for Elementor – Elementor Templates, Widgets & MCP Tools [premium-addons-for-elementor] < 4.10.57 Missing Authorization Medium 5.4 < 4.10.57 4.10.57 2024-12-19

CVE-2024-56225

The Premium Addons for Elementor plugin contains a capability check vulnerability affecting versions 4.10.56 and earlier that allows authenticated users with Contributor permissions or higher to execute unauthorized actions. An attacker with a lower-privilege account could exploit the missing capability verification to perform operations they should not be permitted to access. This flaw was fixed in version 4.10.57, where proper capability checks were implemented to restrict the vulnerable function to authorized users only.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.