Beta

Report

Events Addon for Elementor <= 2.1.3 is vulnerable to Broken Access Control vulnerability

Unauthenticated
Published
2023-11-15

The Events Addon for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the naevents_bw_settings_save_func(), naevents_bw_toggle_submit_func(), naevents_pro_settings_save_func(), naevents_pro_toggle_submit_func() and naevents_uw_settings_save_func() functions all hooked via nopriv AJAX actions in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to modify the plugin's settings.

CVSS

Score:6.5

Severity:Medium

Version: 2.1.3

There is a patch available in v2.1.4 and we strongly recommend you update to this version as soon as possible.