First published: Tue Jun 04 2024(Updated: )
Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Code Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.66.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Unlimited Elements For Elementor | <1.5.67 | |
Unlimited Elements for Elementor | <=1.5.66 | |
WordPress Unlimited Elements For Elementor | <=1.5.66 |
Update to 1.5.67 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-33930 is rated as a critical vulnerability due to its potential for code injection via unrestricted file uploads.
To fix CVE-2023-33930, update Unlimited Elements For Elementor to version 1.5.67 or later.
CVE-2023-33930 allows for the upload of files with dangerous types, including potentially executable code, posing significant security risks.
The impacts of CVE-2023-33930 include unauthorized code execution and potential full server compromise.
CVE-2023-33930 affects all installations of Unlimited Elements For Elementor prior to version 1.5.67.