PT-2023-23260 · Elementor · Elementor Pro

·

CVE-2023-3124

·

Published

2023-06-07

·

Updated

2023-06-13

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elementor Pro versions up to, and including, 3.11.6
Description The issue allows authenticated attackers with subscriber-level capabilities to update arbitrary site options, potentially leading to privilege escalation, due to a missing capability check on the update page option function.
Recommendations For versions up to, and including, 3.11.6, update to a version that includes a fix for the missing capability check in the update page option function to prevent unauthorized data modification.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-3124

Affected Products

Elementor Pro