CVE-2023-47504
MEDIUMElementor Website Builder <= 3.16.4 - Improper Authentication
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-47504. PoCs published by davidxbors.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-47504, which targets an arbitrary attachment read vulnerability in the Elementor Website Builder Plugin for WordPress. The exploit requires a low-privileged account (subscriber) and access to the target's `wp-config.php` file to generate a valid nonce for clearing the Elementor cache.
Description
Improper Authentication vulnerability in Elementor Elementor Website Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Elementor Website Builder: from n/a through 3.16.4.
Exploits (1)
This repository contains a functional exploit for CVE-2023-47504, which targets an arbitrary attachment read vulnerability in the Elementor Website Builder Plugin for WordPress. The exploit requires a low-privileged account (subscriber) and access to the target's `wp-config.php` file to generate a valid nonce for clearing the Elementor cache.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N