CVE-2023-32243

CRITICAL EXPLOITED IN THE WILD NUCLEI

Wpdeveloper Essential Addons For Elementor - Authentication Bypass

Title source: rule

Description

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

Exploits (11)

nomisec WORKING POC 81 stars
by RandomRobbieBF · remote
https://github.com/RandomRobbieBF/CVE-2023-32243
nomisec WORKING POC 4 stars
by Jenderal92 · remote
https://github.com/Jenderal92/WP-CVE-2023-32243
nomisec WORKING POC 3 stars
by gbrsh · remote
https://github.com/gbrsh/CVE-2023-32243
nomisec WORKING POC 2 stars
by thatonesecguy · remote
https://github.com/thatonesecguy/Wordpress-Vulnerability-Identification-Scripts
nomisec WORKING POC 2 stars
by shaoyu521 · remote
https://github.com/shaoyu521/Mass-CVE-2023-32243
nomisec WORKING POC 1 stars
by little44n1o · remote
https://github.com/little44n1o/cve-2023-32243
nomisec WORKING POC
by YouGina · poc
https://github.com/YouGina/CVE-2023-32243
nomisec WORKING POC
by manavvedawala2 · remote
https://github.com/manavvedawala2/CVE-2023-32243-proof-of-concept
nomisec WRITEUP
by dev0558 · poc
https://github.com/dev0558/CVE-2023-32243-Detection-and-Mitigation-in-WordPress

Nuclei Templates (1)

WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset
CRITICALVERIFIEDby DhiyaneshDK,Vikas Kundu

Scores

CVSS v3 9.8
EPSS 0.9354
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2023-05-18
InTheWild.io 2023-05-27

Classification

CWE
CWE-287
Status published

Affected Products (1)

wpdeveloper/essential_addons_for_elementor < 5.7.1

Timeline

Published May 12, 2023
Tracked Since Feb 18, 2026