Essential Addons for Elementor
cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:wordpress:*:*
- <= 6.5.13
A privilege escalation vulnerability exists in the Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress, affecting all versions through 6.5.13. The issue arises from inadequate role validation in the 'register_user' function, which only prevents the 'administrator' role from being assigned. This flaw allows authenticated attackers with author-level access or higher to create new user accounts with elevated privileges, such as editor rights.
Exploitation of this vulnerability allows authenticated users with author-level access to create new user accounts with editor privileges, thereby escalating their rights and access within the WordPress site.
Users are advised to update the Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin to version 6.6.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.