CVE-2021-4446: Essential Addons for Elementor <= 4.6.4 - Missing Authorization
The Essential Addons for Elementor plugin for WordPress is vulnerable to authorization bypass in versions up to and including 4.6.4 due to missing capability checks and nonce disclosure. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to perform many unauthorized actions such as changing settings and installing arbitrary plugins.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-4446?
CVE-2021-4446 has a critical severity rating due to its potential for authorization bypass.
How do I fix CVE-2021-4446?
To fix CVE-2021-4446, update the Essential Addons for Elementor plugin to version 4.6.5 or later.
What versions of Essential Addons for Elementor are affected by CVE-2021-4446?
CVE-2021-4446 affects all versions of the Essential Addons for Elementor plugin up to and including 4.6.4.
Who can exploit CVE-2021-4446?
CVE-2021-4446 can be exploited by authenticated attackers with minimal permissions, such as a subscriber.
What type of vulnerability is CVE-2021-4446?
CVE-2021-4446 is an authorization bypass vulnerability caused by missing capability checks and nonce disclosure.