CVE-2023-39993: WordPress ElementsKit Lite plugin <= 2.9.0 - Broken Access Control vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in Wpmet Elements kit Elementor addons.This issue affects Elements kit Elementor addons: from n/a through 2.9.0.
Affected Software
2 affected components
Wpmet Elements Kit Elementor addons<=2.9.0
Wpmet ElementsKit Lite<=2.9.0
Remediation
Information
Update to 2.9.1 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-39993?
CVE-2023-39993 has been classified as a medium severity vulnerability due to its missing authorization issue.
2
How do I fix CVE-2023-39993?
To resolve CVE-2023-39993, update Wpmet Elements Kit Elementor addons to version 2.9.1 or later.
3
What versions of Wpmet Elements Kit Elementor addons are affected by CVE-2023-39993?
CVE-2023-39993 affects Wpmet Elements Kit Elementor addons versions up to and including 2.9.0.
4
What type of vulnerability is CVE-2023-39993?
CVE-2023-39993 is classified as a missing authorization vulnerability.
5
Who is the vendor of the software affected by CVE-2023-39993?
The vendor of the affected software is Wpmet.