The Plus Addons for Elementor PRO <= 4.1.9 & The Plus Addons for Elementor <= 2.0.6 - Authenticated (Contributor+) Privilege Escalation
Published Mar 7, 2023
8.8
HIGHCVSS 3.1
EPSS 0.89%
Description
The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 4.1.9 (pro) and 2.0.6 (free). The plugin adds a registration form to the Elementor page builders functionality. As part of the registration form, users can choose which role to set as the default for users upon registration. This field is not hidden for lower-level users so any user with access to the Elementor page builder, such as contributors, can set the default role to administrator. Since contributors can not publish posts, only author+ users can elevate privileges without interaction via a site administrator (to approve a post).
Affected products
-
- Version 0StatusaffectedConstraints<=4.1.9
- Version
-
- Version 0StatusaffectedConstraints<=2.0.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Posimyththemes | The Plus Addons for Elementor Page Builder Pro | unaffected |
| ||||||
| Posimyththemes | n/a | unaffected |
|
- ≤ 2.0.6
- ≤ 4.1.9
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Jan 13, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.89% (0.00885) | 57.76th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.89% (0.00885) | 54.36th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.11% (0.00108) | 25.97th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.52% (0.01518) | 69.49th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.11% (0.00108) | 26.59th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00104) | 44.28th | v3 (v2023.03.01) |
| Mar 13, 2024 | 0.09% (0.00089) | 36.50th | v3 (v2023.03.01) |
| Feb 5, 2024 | 0.06% (0.00058) | 22.67th | v3 (v2023.03.01) |
| Mar 15, 2023 | 0.05% (0.00050) | 16.97th | v3 (v2023.03.01) |
| Mar 8, 2023 | 0.04% (0.00043) | 6.99th | v3 (v2023.03.01) |
References (3)
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2514618%40the-plus-addons-for-elementor-page-builder&new=2514618%40the-plus-addons-for-elementor-page-builder&sfp_email=&sfph_mail= Third Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/96388c82-2392-42b3-b0a0-c3d92910fb5c Third Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/96388c82-2392-42b3-b0a0-c3d92910fb5c?source=cve
Change history (0)
No recorded changes yet.