Description
WordPress Plugin PowerPack Pro for Elementor is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin PowerPack Pro for Elementor version 2.10.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.10.15 or latest
References
Related Vulnerabilities
WordPress Plugin Awesome Support-WordPress HelpDesk & Support Cross-Site Scripting (6.0.6)
Apache HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2018-17189)
Oracle HTTP Server Out-of-bounds Read Vulnerability (CVE-2018-16890)
WordPress Plugin All-in-One Event Calendar Multiple Cross-Site Scripting Vulnerabilities (1.5)