First published: Wed Apr 24 2024(Updated: )
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Elementor Website Builder | <=3.16.4 | |
Elementor | <=3.16.4 | |
Elementor Website Builder | <3.16.5 |
Update to 3.16.5 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47504 has a high severity rating due to its potential to allow unauthorized access to functionality not properly constrained by access control lists.
To fix CVE-2023-47504, update the Elementor Website Builder to a version higher than 3.16.4.
CVE-2023-47504 affects Elementor Website Builder versions from n/a through 3.16.4.
CVE-2023-47504 is classified as an improper authentication vulnerability affecting Elementor.
Yes, CVE-2023-47504 is exploitable, allowing attackers to gain access to restricted functionality.