cleantalk
Vulnerabilities and Security Researches

Elementor Website Builder – More than Just a Page Builder, CVE-2023-0329

CVE, Research URL

CVE-2023-0329

Published on
May 30, 2023
Research Description
The Elementor Website Builder WordPress plugin before 3.12.2 does not properly sanitize and escape the Replace URL parameter in the Tools module before using it in a SQL statement, leading to a SQL injection exploitable by users with the Administrator role.
Affected versions
Min -, max 3.12.2.
Status
vulnerable