Description
WordPress Plugin Elementor Website Builder is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently import/export content which may lead to potentially complete site compromise. WordPress Plugin Elementor Website Builder version 1.7.12 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.1 or latest
References
http://www.pritect.net/blog/elementor-page-builder-1-8-allows-logged-users-unrestricted-editing
https://plugins.svn.wordpress.org/elementor/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Contact Form for WordPress-Ultimate Form Builder Lite Cross-Site Scripting (1.3.3)
Oracle JRE CVE-2012-5081 Vulnerability (CVE-2012-5081)
Serendipity Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-5476)
WordPress Plugin Coming Soon & Maintenance Mode Page PHP Object Injection (1.42)
WordPress Plugin Gwolle Guestbook Multiple Vulnerabilities (2.1.0)