Cross-Site Request Forgery in Elementor Addon Elements Plugin for WordPress
CVE-2023-4689
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 November 2023
What is CVE-2023-4689?
The Elementor Addon Elements plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate or absent nonce validation in the 'eae_save_elements' function. This flaw allows unauthenticated attackers to potentially enable or disable elements by deceiving an administrator into executing a malicious action, such as clicking on a crafted link. Proper nonce validation is critical to preventing such unauthorized actions and ensuring the security of the site.
Affected Version(s)
Addon Elements for Elementor (formerly Elementor Addon Elements) 0 <= 1.12.7