Prime Addons for Elementor Insecure Direct Object Reference Vulnerability

Vulnerability

A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Prime Addons for Elementor plugin for WordPress, affecting all versions through 2.0.1. The vulnerability arises from missing validation on a user-controlled key in the 'pae_global_block' shortcode. This flaw enables authenticated attackers with Contributor-level access and above to access and extract information from non-public posts, including drafts, private, password-protected, and restricted content. The issue specifically pertains to posts created with Elementor.

Impact

Exploitation of this vulnerability allows for unauthorized access to and extraction of information from non-public posts, including drafts, private, password-protected, and restricted content, created with Elementor.

Remediation

Users are advised to update the Prime Addons for Elementor plugin to version 2.0.2 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.8
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.