8.8
CVSSv3

CVE-2023-3124

Published: 07/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

Vulnerable Product Search on Vulmon Subscribe to Product

elementor elementor pro

Vendor Advisories

Check Point Reference: CPAI-2023-1700 Date Published: 23 May 2024 Severity: High ...

Github Repositories

CVE-2023-3124 PoC

CVE-2023-3124 CVE-2023-3124 Proof of Concept This is a proof of concept (PoC) exploit for CVE-2023-3124, a vulnerability in WordPress Elementor Pro plugin Description: The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3116 This makes