Rewterz

Rewterz Threat Alert – Earth Preta aka Mustang Panda APT Group – Active IOCsIOCs

May 12, 2023
Rewterz

Rewterz Threat Advisory – CVE-2023-20877 – VMware Aria Operations Vulnerability

May 12, 2023

Rewterz Threat Advisory – CVE-2023-32243 – WordPress Plugin Vulnerability

Severity

High

Analysis Summary

CVE-2023-32243

A vulnerability has been found in Essential Addons for Elementor Plugin on WordPress. Affected by this vulnerability is some unknown functionality. The manipulation with an unknown input leads to a password recovery vulnerability. The software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. As an impact it is known to affect confidentiality, integrity, and availability.

Impact

  • Privilege Escalation

Indicators Of Compromise

CVE

  • CVE-2023-32243

Affected Vendors

WordPress

Affected Products

  • Essential Addons for Elementor Plugin

Remediation

Upgrade to the latest version of Elementor Plugin, available from the WordPress Web site.

WordPress Web site

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.