CVE-2023-48759: WordPress JetElements For Elementor plugin <= 2.6.13 - Unauthenticated Arbitrary Attachment Download vulnerability
Published Jun 19, 2024
·Updated
Missing Authorization vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.13.
Affected Software
1 affected component
Crocoblock Jetelements Wordpress<2.6.13.1
Remediation
Information
Update to 2.6.13.1 or a higher version.
Event History
Jun 19, 2024
CVE Published
via MITRE·10:32 AM
Data Sourced
via MITRE·10:32 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-48759?
CVE-2023-48759 has a medium severity rating due to its potential for unauthorized access.
2
How do I fix CVE-2023-48759?
To fix CVE-2023-48759, update JetElements For Elementor to version 2.6.14 or later.
3
What software is affected by CVE-2023-48759?
CVE-2023-48759 affects JetElements For Elementor versions up to and including 2.6.13.
4
What kind of vulnerability is CVE-2023-48759?
CVE-2023-48759 is a missing authorization vulnerability that allows unauthorized users to access certain features.
5
Who is responsible for addressing CVE-2023-48759?
Website administrators using affected versions of JetElements For Elementor are responsible for addressing CVE-2023-48759.