Beta

Report

Elementor Pro <= 3.13.0 is vulnerable to Auth. Broken Access Control vulnerability

Subscriber
Published
2023-06-19

The Elementor Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on several functions in versions up to, and including, 3.13.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions like modifying screenshots,

CVSS

Score:5.4

Severity:Medium

Version: 3.13.0

There is a patch available in v3.13.1 and we strongly recommend you update to this version as soon as possible.