9.8
CRITICAL
CVE-2023-32243
WPDeveloper Essential Addons for Elementor Authentication Bypass
Description

Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.

INFO

Published Date :

May 12, 2023, 8:15 a.m.

Last Modified :

Nov. 21, 2024, 8:02 a.m.

Remotely Exploitable :

Yes !

Impact Score :

5.9

Exploitability Score :

3.9
Public PoC/Exploit Available at Github

CVE-2023-32243 has a 16 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2023-32243 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Wpdeveloper essential_addons_for_elementor

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

None

Updated: 2 days, 15 hours ago
0 stars 0 fork 0 watcher
Born at : April 29, 2025, 9:41 p.m. This repo has been linked 1 different CVEs too.

PoC. Severity critical.

Shell Ruby Python PHP

Updated: 1 year, 8 months ago
0 stars 1 fork 1 watcher
Born at : Aug. 10, 2023, 8:31 p.m. This repo has been linked 18 different CVEs too.

PoC. Severity critical.

cve-2023-1671 cve-2023-27350 cve-2023-2868 cve-2023-3519 cve-2023-34960 exploit poc cve-2023-28121 cve-2023-28771 cve-2023-35885 cve-2023-38646 cve-2023-34124 citrix sonicwall cve-2023-4596 cve-2023-26469 cve-2023-23333 ivanti cve-2023-40044 cve-2023-22515

Shell Python Ruby PHP

Updated: 1 month ago
70 stars 16 fork 16 watcher
Born at : Aug. 5, 2023, 11:02 a.m. This repo has been linked 38 different CVEs too.

Mass-CVE-2023-32243

Python

Updated: 2 months, 2 weeks ago
2 stars 1 fork 1 watcher
Born at : July 29, 2023, 8:43 p.m. This repo has been linked 1 different CVEs too.

Wordpress CVE-2023-32243

cve-2023-32243 exploit-wordpress wordpress wordpress-exploit wordpress-vulnerability

Python

Updated: 4 months, 3 weeks ago
5 stars 4 fork 4 watcher
Born at : July 3, 2023, 4:16 a.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 year, 10 months ago
0 stars 0 fork 0 watcher
Born at : June 26, 2023, 8:17 a.m. This repo has been linked 1 different CVEs too.

just an ordinary exploit

Python

Updated: 1 year, 2 months ago
3 stars 3 fork 3 watcher
Born at : June 8, 2023, 6:59 p.m. This repo has been linked 1 different CVEs too.

Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

Python

Updated: 1 year, 9 months ago
2 stars 0 fork 0 watcher
Born at : May 29, 2023, 11:42 a.m. This repo has been linked 1 different CVEs too.

None

Dockerfile Python JavaScript HTML CSS Shell C SCSS C# PHP

Updated: 11 months ago
17 stars 0 fork 0 watcher
Born at : May 28, 2023, 2:01 p.m. This repo has been linked 1 different CVEs too.

Vulnerable docker to test for: CVE-2023-32243

JavaScript CSS PHP SCSS

Updated: 1 year, 11 months ago
0 stars 0 fork 0 watcher
Born at : May 24, 2023, 7:50 p.m. This repo has been linked 1 different CVEs too.

None

Python

Updated: 1 year, 11 months ago
0 stars 0 fork 0 watcher
Born at : May 23, 2023, 6:38 p.m. This repo has been linked 1 different CVEs too.

None

Updated: 1 year, 11 months ago
0 stars 0 fork 0 watcher
Born at : May 23, 2023, 6:36 p.m. This repo has been linked 1 different CVEs too.

CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation

wordpress-exploit wordpress-plugin cve-2023-32243

Python

Updated: 2 weeks ago
81 stars 22 fork 22 watcher
Born at : May 15, 2023, 9:39 a.m. This repo has been linked 1 different CVEs too.

Exploit for CVE-2023-32243 - Unauthorized Account Takeover.

Python

Updated: 3 weeks, 3 days ago
3 stars 3 fork 3 watcher
Born at : May 14, 2023, 7:32 p.m. This repo has been linked 1 different CVEs too.

poc

Python

Updated: 1 year, 11 months ago
1 stars 0 fork 0 watcher
Born at : May 13, 2023, 7:35 p.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2023-32243 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2023-32243 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference http://packetstormsecurity.com/files/172457/WordPress-Elementor-Lite-5.7.1-Arbitrary-Password-Reset.html
    Added Reference https://patchstack.com/articles/critical-privilege-escalation-in-essential-addons-for-elementor-plugin-affecting-1-million-sites?_s_id=cve
    Added Reference https://patchstack.com/database/vulnerability/essential-addons-for-elementor-lite/wordpress-essential-addons-for-elementor-plugin-5-4-0-5-7-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • Initial Analysis by [email protected]

    May. 23, 2023

    Action Type Old Value New Value
    Added CVSS V3.1 NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Changed Reference Type http://packetstormsecurity.com/files/172457/WordPress-Elementor-Lite-5.7.1-Arbitrary-Password-Reset.html No Types Assigned http://packetstormsecurity.com/files/172457/WordPress-Elementor-Lite-5.7.1-Arbitrary-Password-Reset.html Exploit, Third Party Advisory, VDB Entry
    Changed Reference Type https://patchstack.com/articles/critical-privilege-escalation-in-essential-addons-for-elementor-plugin-affecting-1-million-sites?_s_id=cve No Types Assigned https://patchstack.com/articles/critical-privilege-escalation-in-essential-addons-for-elementor-plugin-affecting-1-million-sites?_s_id=cve Exploit, Third Party Advisory
    Changed Reference Type https://patchstack.com/database/vulnerability/essential-addons-for-elementor-lite/wordpress-essential-addons-for-elementor-plugin-5-4-0-5-7-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve No Types Assigned https://patchstack.com/database/vulnerability/essential-addons-for-elementor-lite/wordpress-essential-addons-for-elementor-plugin-5-4-0-5-7-1-unauthenticated-privilege-escalation-vulnerability?_s_id=cve Third Party Advisory
    Added CWE NIST CWE-287
    Added CPE Configuration OR *cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:*:wordpress:*:* versions from (including) 5.4.0 up to (excluding) 5.7.1
  • CVE Modified by [email protected]

    May. 18, 2023

    Action Type Old Value New Value
    Added Reference http://packetstormsecurity.com/files/172457/WordPress-Elementor-Lite-5.7.1-Arbitrary-Password-Reset.html [No Types Assigned]
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2023-32243 is associated with the following CWEs:

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

93.74 }} 0.10%

score

0.99843

percentile

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
© cvefeed.io
Latest DB Update: May. 02, 2025 14:00