The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Jan 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpdeveloper
Wpdeveloper essential Addons For Elementor |
|
CPEs | cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:* | |
Vendors & Products |
Wpdeveloper
Wpdeveloper essential Addons For Elementor |
Wed, 16 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Oct 2024 07:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins. | |
Title | Essential Addons for Elementor <= 4.6.4 - Missing Authorization | |
Weaknesses | CWE-862 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-10-16T15:34:14.629Z
Reserved: 2024-10-15T18:28:06.856Z
Link: CVE-2021-4446

Updated: 2024-10-16T15:33:59.590Z

Status : Analyzed
Published: 2024-10-16T07:15:10.447
Modified: 2025-01-10T14:46:34.020
Link: CVE-2021-4446

No data.