Description
WordPress Plugin Elementor Website Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently upload SVG files even if not allowed. WordPress Plugin Elementor Website Builder version 3.0.13 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.0.14 or latest
References
Related Vulnerabilities
MySQL CVE-2015-4761 Vulnerability (CVE-2015-4761)
Liferay DXP Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-8980)
Jboss EAP Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-10172)
WordPress Plugin Meta Box-WordPress Custom Fields Framework Arbitrary File Deletion (4.16.2)