Description
WordPress Plugin Ultimate Addons for Elementor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create subscriber-level users, even if registration is disabled. WordPress Plugin Ultimate Addons for Elementor version 1.24.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.24.2 or latest
References
Related Vulnerabilities
MySQL CVE-2013-3802 Vulnerability (CVE-2013-3802)
Joomla Improper Authentication Vulnerability (CVE-2022-23795)
Chamilo Improper Privilege Management Vulnerability (CVE-2022-27421)
WordPress Plugin WordPress Download Manager Multiple Security Bypass Vulnerabilities (2.6.92)
WordPress Plugin Permalink Manager Lite Cross-Site Scripting (2.2.14)