The Better Elementor Addons plugin for WordPress has a vulnerability that allows users who have been authenticated with a subscriber-level access or higher to make unauthorized changes to the data stored in the plugin. This vulnerability affects versions up to and including 1.3.5 and is caused by a missing capability check on the bea_admin_ajax() function that is accessed via an AJAX action.