cve/2023/CVE-2023-3124.md
2024-05-25 21:48:12 +02:00

935 B

CVE-2023-3124

Description

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

POC

Reference

No PoCs from references.

Github