CVE-2023-35050: WordPress Elementor Pro plugin <= 3.13.0 - Auth. Broken Access Control vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in Elementor Elementor Pro.This issue affects Elementor Pro: from n/a through 3.13.0.
Affected Software
2 affected components
Elementor Website Builder<=3.13.0
WordPress Elementor Pro<=3.13.0
Remediation
Information
Update to 3.13.1 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-35050?
CVE-2023-35050 has been categorized as a missing authorization vulnerability.
2
How do I fix CVE-2023-35050?
To fix CVE-2023-35050, update Elementor Pro to the latest version beyond 3.13.0.
3
Which versions of Elementor Pro are affected by CVE-2023-35050?
CVE-2023-35050 affects all versions of Elementor Pro from n/a to 3.13.0.
4
What type of vulnerability is CVE-2023-35050?
CVE-2023-35050 is classified as a missing authorization vulnerability.
5
What impact does CVE-2023-35050 have on Elementor Pro users?
CVE-2023-35050 can potentially allow unauthorized users to access restricted functionalities within Elementor Pro.