PT-2024-15073 · WordPress · Unlimited Elements For Elementor
Nex Team
·
Published
2024-05-29
·
Updated
2025-01-30
·
CVE-2023-6743
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Unlimited Elements For Elementor plugin versions up to, and including, 1.5.89
Description
The issue allows authenticated attackers with contributor access and above to execute code on the server via the template import functionality. This enables remote code execution, posing a significant risk.
Recommendations
For versions up to, and including, 1.5.89, update to a version higher than 1.5.89 to resolve the issue.
As a temporary workaround, consider restricting access to the template import functionality to minimize the risk of exploitation.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unlimited Elements For Elementor