CVE-2023-47504: WordPress Elementor plugin <= 3.16.4 - Auth. Arbitrary Attachment Read vulnerability
Published Apr 24, 2024
·Updated
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.
Affected Software
3 affected components
Elementor Website Builder<=3.16.4
WordPress Elementor<=3.16.4
Elementor Website Builder WordPress<3.16.5
Remediation
Information
Update to 3.16.5 or a higher version.
Event History
Apr 24, 2024
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47504?
CVE-2023-47504 has a high severity rating due to its potential to allow unauthorized access to functionality not properly constrained by access control lists.
2
How do I fix CVE-2023-47504?
To fix CVE-2023-47504, update the Elementor Website Builder to a version higher than 3.16.4.
3
What systems are affected by CVE-2023-47504?
CVE-2023-47504 affects Elementor Website Builder versions from n/a through 3.16.4.
4
What kind of vulnerability is CVE-2023-47504?
CVE-2023-47504 is classified as an improper authentication vulnerability affecting Elementor.
5
Is CVE-2023-47504 exploitable?
Yes, CVE-2023-47504 is exploitable, allowing attackers to gain access to restricted functionality.