Skip to content

Security Vulnerabilities in Elementor Plugins: What You Need to Know and How to Fix Them

Tutorials & Guides  ·   ·   ·  Updated on  ·  3 min Reading time

In the world of website development and management, the security and reliability of your plugins are crucial. Today we want to inform you about two critical vulnerabilities discovered in two widely used plugins for WordPress: Essential Addons for Elementor and Elementor Pro in combination with WooCommerce.

What are the vulnerabilities?

The first vulnerability, known as CVE-2023-32243, was discovered in the Essential Addons for Elementor plugin, a popular WordPress plugin with over a million active installations. This vulnerability affects the plugin's password reset function, and due to the absence of password reset key validation, an attacker can directly change any user's password on the affected website without proper verification.

The second vulnerability affects websites that use Elementor Pro and WooCommerce together. With this vulnerability, attackers can gain full access to the system if an affected installation of the Pro version is used together with WooCommerce. This vulnerability affects versions 3.11.6 and earlier of the Elementor Pro plugin.

How does this affect you?

If you use Essential Addons for Elementor in version 5.4.0 to 5.7.2, you could be affected by the vulnerability. For Elementor Pro in combination with WooCommerce, the vulnerability only affects those using version 3.11.6 or earlier.

Were these vulnerabilities actively exploited?

Yes, both vulnerabilities were actively exploited. There are reports that attackers used the vulnerabilities in Essential Addons for Elementor and Elementor Pro to gain administrator access to WordPress websites.

How can you fix these vulnerabilities?

The developers of both plugins have released security updates that fix these vulnerabilities.

For Essential Addons for Elementor, you should update the plugin to version 5.7.2 or higher.

For Elementor Pro in combination with WooCommerce, you should update the plugin to version 3.11.7 or higher.

Conclusion

The security of your website should always be a top priority. It's crucial to stay up to date and make sure all your plugins are current in order to prevent or fix vulnerabilities. At Prepaid-Host, we offer web hosting solutions that meet your security needs. Our server location in Frankfurt am Main ensures your website is fast and reliable, which in turn makes your website more secure. By taking the factors mentioned above into account and carrying out the recommended steps, you can make sure your website is safe for both search engines and your visitors.

The world of web hosting is constantly evolving, and new security threats can appear at any time. But don't worry, we're here to support you. If you have questions or need assistance, don't hesitate to contact us. Together, we can make sure your website stays safe and protected.

Frequently asked questions

What is CVE-2023-32243?
It's a vulnerability in the Essential Addons for Elementor plugin affecting the password reset function. Due to missing password reset key validation, an attacker can directly change any user's password on the affected website without proper verification.
Which plugin versions are affected?
Essential Addons for Elementor versions 5.4.0 to 5.7.2, and Elementor Pro in combination with WooCommerce in versions 3.11.6 and earlier.
How do I fix these vulnerabilities?
Update Essential Addons for Elementor to version 5.7.2 or higher, and update Elementor Pro to version 3.11.7 or higher if you use it together with WooCommerce.
Prepaid-Host.com is itself a provider of servers, web hosting and domains, and reports here on its own market. How we handle that is set out in our disclosure statement.