CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-33930

CVSS 9.1v3.1pub. 2024-06-04upd. 2025-02-05

Unrestricted Upload of File with Dangerous Type vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Code Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.66.

🤖 AI Analysis
How it works

The vulnerability, classified as CWE-434, involves insufficient validation of uploaded file types. An attacker with administrator privileges can upload a file containing malicious code (e.g., webshell) in a format that the server then executes. According to references, the mechanism involves unrestricted ZIP archive extraction, allowing arbitrary files to be placed and executed on the server side. The vulnerability has a scope extending beyond the component (Scope: Changed), indicating potential takeover of resources beyond the plugin itself.

Impact

An attacker can gain the ability to execute arbitrary code on the server (RCE), leading to complete system takeover — compromising confidentiality, integrity, and availability of data and services.

Mitigation & patch

Update the Unlimited Elements For Elementor plugin to a version higher than 1.5.66. Details regarding the patched version are available in the vendor references (Patchstack). Additionally, it is recommended to restrict administrative privileges to trusted users and monitor file uploads on the server.

Who is affected

The Unlimited Elements For Elementor plugin (Free Widgets, Addons, Templates) in versions from the beginning up to and including 1.5.66, running on the WordPress platform.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Unlimited Elements For Elementor

    APP
    Unlimited-Elements
    < 1.5.67
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-49271CRITICAL9.1PL ✓same product

RCE przez Deserialization w pluginie Unlimited Elements For Elementor

CVE-2023-31090CRITICAL9.9PL ✓same product

Unrestricted File Upload umożliwiający Web Shell w pluginie Unlimited Elements For Elementor

CVE-2023-31231CRITICAL9.9PL ✓same product

Unrestricted File Upload w wtyczce Unlimited Elements For Elementor

CVE-2024-45454HIGH7.1same product

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Unlimite...

CVE-2023-31080HIGH8.3same product

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addo...