CVE-2023-3124: Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option
The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the updatepageoption function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/elementor-proto a version that resolves this vulnerability.Fixed in 3.11.6 - Compensating control
Ensure only trusted users (e.g., administrators) can access functionality that can trigger/update WordPress site options; limit subscriber-level accounts’ ability to reach any code paths that call update_page_option.
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3124.
What is the title of the vulnerability?
The title of the vulnerability is 'The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6.'
What is the severity of CVE-2023-3124?
The severity of CVE-2023-3124 is high.
How does CVE-2023-3124 affect Elementor Pro plugin for WordPress?
CVE-2023-3124 allows authenticated attackers with subscriber-level capabilities to update arbitrary page options in the Elementor Pro plugin for WordPress.
How can I fix CVE-2023-3124?
To fix CVE-2023-3124, update the Elementor Pro plugin for WordPress to version 3.11.7 or higher.