Record summary

CVE-2023-3124 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC.

Description

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 7, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 23, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Default status: unaffected

CVE ListThrough 3.11.6affected

Proofs of concept

1

Repository PoCs

GitHubAmirWhiteHat/CVE-2023-3124Repository PoCby AmirWhiteHatStars: 5Not analyzed3 files

5.8 KiB

GitHub

PoC details

References

3