PT-2023-23260 · Elementor · Elementor Pro
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Elementor Pro versions up to, and including, 3.11.6
Description
The issue allows authenticated attackers with subscriber-level capabilities to update arbitrary site options, potentially leading to privilege escalation, due to a missing capability check on the
update page option function.Recommendations
For versions up to, and including, 3.11.6, update to a version that includes a fix for the missing capability check in the
update page option function to prevent unauthorized data modification.Exploit
Correção
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Elementor Pro