One of WordPress’s most popular Elementor plugins, “Essential Addons for Elementor,” was affected by an unauthenticated privilege escalation issue which could allow remote attacks to gain administrator rights on the site.
Essential Addons for Elementor is a collection of 90 extensions for the ‘Elementor’ page builder, used by over one million WordPress sites.
The flaw which was discovered on May 8, 2023 by PatchStack is tracked as CVE-2023-32243 and is an unauthenticated privilege escalation vulnerability on the plugin’s password reset functionality, impacting versions 5.4.0 to 5.7.1.
By exploiting the flaw, it is possible to reset the password of any user as long as their username is known, thus being able to reset the password of the administrator and login on their account.
This vulnerability occurs because this password reset function does not validate a password reset key and instead directly changes the password of the given user.
The consequences of this flaw include unauthorized access to private information, website defacement or deletion, malware distribution to visitors, and brand repercussions such as loss of trust and legal compliance problems.
While remote attackers do not need to authenticate to exploit the CVE-2023-32243 flaw, they need to know a username on the system they are targeting for the malicious password reset.
The fix was released with Essential Addons for Elementor version 5.7.2. All plugin users are recommended to upgrade to the latest version at the earliest.

















Comments