CVE-2023-32243

WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation

Basic Information

CVE State
PUBLISHED
Reserved Date
May 05, 2023
Published Date
May 12, 2023
Last Updated
February 13, 2025
Vendor
WPDeveloper
Product
Essential Addons for Elementor
Description
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
Tags
wordpress nuclei_scanner

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

Score
93.64% (Percentile: 99.83%) as of 2025-05-12

SSVC Information

Exploitation
none
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2023-05-17 09:33:52 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
Wordfence 2023-05-17 09:33:52 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

shaoyu521/Mass-CVE-2023-32243

Type: github • Created: 2023-07-29 20:43:16 UTC • Stars: 2

Mass-CVE-2023-32243

Jenderal92/WP-CVE-2023-32243

Type: github • Created: 2023-07-03 04:16:16 UTC • Stars: 5

Wordpress CVE-2023-32243

RandomRobbieBF/CVE-2023-32243

Type: github • Created: 2023-05-15 09:39:45 UTC • Stars: 81

CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation

gbrsh/CVE-2023-32243

Type: github • Created: 2023-05-14 19:32:50 UTC • Stars: 3

Exploit for CVE-2023-32243 - Unauthorized Account Takeover.

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei