CVE-2023-33922: WordPress Elementor plugin <= 3.13.2 - Broken Access Control vulnerability
Published Jun 11, 2024
·Updated
Missing Authorization vulnerability in Elementor Elementor Website Builder.This issue affects Elementor Website Builder: from n/a through 3.13.2.
Affected Software
1 affected component
Elementor Website Builder WordPress<3.13.3
Remediation
Information
Update to 3.13.3 or a higher version.
Event History
Jun 11, 2024
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-33922?
CVE-2023-33922 is classified as a high-severity vulnerability due to its potential for unauthorized access.
2
How do I fix CVE-2023-33922?
To fix CVE-2023-33922, update Elementor Website Builder to version 3.13.3 or later immediately.
3
What systems are affected by CVE-2023-33922?
CVE-2023-33922 affects Elementor Website Builder versions prior to 3.13.3.
4
What type of vulnerability is CVE-2023-33922?
CVE-2023-33922 is a missing authorization vulnerability, allowing unauthorized users to access restricted content.
5
When was CVE-2023-33922 disclosed?
CVE-2023-33922 was disclosed in 2023, raising awareness about security lapses in Elementor Website Builder.