Unlimited Elements For Elementor (Free Widgets, Addons, Templates), 6dae6dca-7474-4008-9fe5-4c62b9f12d0a
- CVE, Research URL
- Home page URL
-
Security reports for Unlimited Elements For Elementor (Free Widgets, Addons, Templates)
- Published on
- -
- Research Description
- Unlimited Elements for Elementor [unlimited-elements-for-elementor] < 1.5.3 Unauthorised AJAX Calls via Freemius The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.
- Affected versions
-
max 1.5.3.
- Status
-
vulnerable