GSD-2022-1000955
Dashboard / Vulnerabilities / GSD-2022-1000955
GSD-2022-1000955
Summary: Access control check in Elementor WordPress plugin version =<3.6.2
Details: In Elementor WordPress plugin version 3.6.2 and earlier an access control check vulnerability exists. To quote Bill Toulas from BleepingComputer: "The problem lies in the absence of a crucial access check on one of the plugin's files, "module.php", which is loaded on every request during the admin_init action, even for users that are not logged in, the researchers explain." This can be attacked via the network using standard web requests, resulting in remote code execution. This is fixed in version 3.6.3.
References: https://www.bleepingcomputer.com/news/security/critical-flaw-in-elementor-wordpress-plugin-may-affect-500k-sites/, https://www.pluginvulnerabilities.com/2022/04/12/5-million-install-wordpress-plugin-elementor-contains-authenticated-remote-code-execution-rce-vulnerability/
