Access violation vulnerability in Prime Addons for Elementor 2.0.1

The Prime Addons for Elementor plugin for WordPress has a security vulnerability in all versions up to 2.0.1. This vulnerability, known as Insecure Direct Object Reference, is caused by a lack of validation on a key that can be controlled by the user. This means that attackers who are logged in and have Contributor-level access or higher can access information from posts that are not meant to be seen by the public, such as drafts, private posts, and restricted posts. This vulnerability only affects posts that were created with Elementor.

Detected in:

Prime Addons for Elementor fixed vulnerable versions: >= * <= 2.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.