First published: Wed Oct 16 2024(Updated: )
The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPDeveloper Essential Addons for Elementor | <4.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-4446 has a critical severity rating due to its potential for authorization bypass.
To fix CVE-2021-4446, update the Essential Addons for Elementor plugin to version 4.6.5 or later.
CVE-2021-4446 affects all versions of the Essential Addons for Elementor plugin up to and including 4.6.4.
CVE-2021-4446 can be exploited by authenticated attackers with minimal permissions, such as a subscriber.
CVE-2021-4446 is an authorization bypass vulnerability caused by missing capability checks and nonce disclosure.