CVE-2023-33930: WordPress Unlimited Elements For Elementor plugin <= 1.5.66 - Unrestricted Zip Extraction vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Code Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.66.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-33930?
CVE-2023-33930 is rated as a critical vulnerability due to its potential for code injection via unrestricted file uploads.
How do I fix CVE-2023-33930?
To fix CVE-2023-33930, update Unlimited Elements For Elementor to version 1.5.67 or later.
What types of files can be uploaded in CVE-2023-33930?
CVE-2023-33930 allows for the upload of files with dangerous types, including potentially executable code, posing significant security risks.
What are the impacts of CVE-2023-33930?
The impacts of CVE-2023-33930 include unauthorized code execution and potential full server compromise.
Who is affected by CVE-2023-33930?
CVE-2023-33930 affects all installations of Unlimited Elements For Elementor prior to version 1.5.67.