← Back to browse · API

CVE-2023-3124

Severity
HIGH
CVSS
8.8
EPSS
0.2272
Risk score
43.15
CISA KEV
No
PoC
No
Published
2023-06-07
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2023-43810, GHSA-7J8C-J5QM-W6XF
Products
https://elementor.com/:Elementor Website Builder Pro 0 ≤3.11.6
Sources
euvd EUVD-2023-43810

Description

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.

References