CVE-2023-48777: WordPress Elementor plugin 3.3.0-3.18.1 - Arbitrary File Upload vulnerability
Published Mar 26, 2024
·Updated
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor.Com Elementor Website Builder.This issue affects Elementor Website Builder: from 3.3.0 through 3.18.1.
Affected Software
3 affected components
Elementor Website Builder WordPress>=3.3.0<3.18.2
Elementor Website Builder>=3.3.0<=3.18.1
WordPress Elementor plugin>=3.3.0<=3.18.1
Remediation
Information
Update to 3.18.2 or a higher version.
Event History
Mar 26, 2024
CVE Published
via MITRE·08:49 PM
Data Sourced
via MITRE·08:49 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-48777?
CVE-2023-48777 is considered a high-severity vulnerability due to its unrestricted file upload nature.
2
How do I fix CVE-2023-48777?
To fix CVE-2023-48777, update Elementor Website Builder to version 3.18.2 or later.
3
What versions of Elementor are affected by CVE-2023-48777?
CVE-2023-48777 affects Elementor Website Builder versions from 3.3.0 to 3.18.1.
4
Can CVE-2023-48777 lead to take over a website?
Yes, CVE-2023-48777 can allow attackers to upload malicious files, potentially leading to full website compromise.
5
Is CVE-2023-48777 specific to a certain environment?
CVE-2023-48777 specifically affects WordPress websites using the Elementor plugin.