Medical Addon for Elementor Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Medical Addon for Elementor plugin for WordPress, affecting all versions through 1.6.2. The vulnerability arises from the 'namedical_elementor_template' shortcode, which lacks proper validation on a user-controlled key. This flaw enables authenticated attackers with Contributor-level access and above to access and read the content of draft, pending, and private posts.

Impact

Exploitation of this vulnerability allows authenticated users with Contributor-level access and above to access and read the content of draft, pending, and private posts, which could lead to unauthorized disclosure of sensitive information.

Remediation

Users are advised to update the Medical Addon for Elementor plugin to version 1.6.3 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.5
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.