CVE-2023-2189: Elementor Addons, Widgets and Enhancements – Stax <= 1.4.3 - Missing Authorization in toggle_widget
The Elementor Addons, Widgets and Enhancements – Stax plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the togglewidget function in versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to enable or disable Elementor widgets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2189?
CVE-2023-2189 is classified as a critical vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2023-2189?
To fix CVE-2023-2189, update the Stax plugin for WordPress to version 1.4.4 or later.
Who is affected by CVE-2023-2189?
CVE-2023-2189 affects users of the Stax plugin for WordPress versions up to and including 1.4.3.
What does CVE-2023-2189 allow an attacker to do?
CVE-2023-2189 allows authenticated attackers to modify data without proper authorization due to a missing capability check.
Which WordPress versions are impacted by CVE-2023-2189?
WordPress installations using the Stax plugin versions 1.4.3 and earlier are impacted by CVE-2023-2189.