Rewterz
Rewterz Threat Alert – Earth Preta aka Mustang Panda APT Group – Active IOCsIOCs
May 12, 2023
Rewterz
Rewterz Threat Advisory – CVE-2023-20877 – VMware Aria Operations Vulnerability
May 12, 2023

Rewterz Threat Advisory – CVE-2023-32243 – WordPress Plugin Vulnerability

Severity

High

Analysis Summary

CVE-2023-32243

A vulnerability has been found in Essential Addons for Elementor Plugin on WordPress. Affected by this vulnerability is some unknown functionality. The manipulation with an unknown input leads to a password recovery vulnerability. The software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. As an impact it is known to affect confidentiality, integrity, and availability.

Impact

  • Privilege Escalation

Indicators Of Compromise

CVE

  • CVE-2023-32243

Affected Vendors

WordPress

Affected Products

  • Essential Addons for Elementor Plugin

Remediation

Upgrade to the latest version of Elementor Plugin, available from the WordPress Web site.

WordPress Web site