Lucene search

K
wpvulndbWpvulndbWPVDB-ID:8F1DE960-73DA-414A-AD72-09C14366B8E2
HistoryFeb 09, 2024 - 12:00 a.m.

Element Pack Elementor Addons < 5.4.12 - Missing Authorization via bdt_duplicate_as_draft

2024-02-0900:00:00
wpscan.com
10
wordpress
security vulnerability
data modification
capability check
authenticated attackers
contributor access
post duplication

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

Description The Element Pack Elementor Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘bdt_duplicate_as_draft’ function in versions up to, and including, 5.4.11. This makes it possible for authenticated attackers, with contributor-level access and above, to duplicate other user’s posts and set their user as the author of the duplicated post.

AI Score

6.7

Confidence

High

EPSS

0

Percentile

9.0%

Related for WPVDB-ID:8F1DE960-73DA-414A-AD72-09C14366B8E2