Access violation vulnerability in Element Pack Elementor Addons (Header Footer, Free Template Library, Grid, Carousel, Table, Parallax Animation, Register Form, Twitter Grid) 5.4.11

The Element Pack Elementor Addons plugin for WordPress has a security issue that allows unauthorized changes to be made to data. This happens because the ‘bdt_duplicate_as_draft’ function in versions up to 5.4.11 does not have a check for proper permissions. This means that someone with at least contributor-level access can duplicate posts from other users and claim them as their own.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.