GSD-2022-1000955

    Dashboard / Vulnerabilities / GSD-2022-1000955

    GSD-2022-1000955

    Published: 13 Apr 2022Last Modified: 14 Mar 2023

    Summary: Access control check in Elementor WordPress plugin version =<3.6.2

    Details: In Elementor WordPress plugin version 3.6.2 and earlier an access control check vulnerability exists. To quote Bill Toulas from BleepingComputer: "The problem lies in the absence of a crucial access check on one of the plugin's files, "module.php", which is loaded on every request during the admin_init action, even for users that are not logged in, the researchers explain." This can be attacked via the network using standard web requests, resulting in remote code execution. This is fixed in version 3.6.3.

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GSD-2022-1000955 | CVE-DB