CyberRota Analysis
AI-GeneratedThe Unlimited Elements For Elementor WordPress plugin prior to version 2.0.20 is vulnerable due to a lack of capability checks on an AJAX action, allowing authenticated attackers with subscriber-level access to inject arbitrary PHP objects through deserialized attacker-controlled data. This vulnerability can lead to unauthorized code execution, potentially compromising the integrity of the WordPress site. WordPress site administrators using affected versions should prioritize updating to version 2.0.20 or later to mitigate this risk.
Original NVD Description
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable action to editor-level, and the issue was fully resolved in 2.0.20.