CVE-2023-32243 — Essential Addons For Elementor
CRITICALCVE-2023-32243 is a critical-severity (CVSS 9.8) Improper Authentication vulnerability in wpdeveloper essential addons for elementor. 10 public exploit references exist, so weaponization risk is real. A fix is available — see the affected versions and patch details below.
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
Exploitation Status
No confirmed exploitation observed yet
- CISA assesses this as automatable — exploitation doesn’t require manual, per-target effort, which raises the odds of mass scanning and opportunistic attacks.
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2023-32243.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2023-32243 by exploitation likelihood (EPSS) against impact (CVSS). In the shaded patch-first corner (EPSS 50%+, CVSS 7.0+).
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the 50–90% band (highlighted). Counts from FIRST.org, log-scaled.
Description
Improper Authentication vulnerability in WPDeveloper Essential Addons for Elementor allows Privilege Escalation. This issue affects Essential Addons for Elementor: from 5.4.0 through 5.7.1.
Affected Products
essential addons for elementorwpdeveloperResearch use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
Improper Authentication vulnerability in WPDeveloper Essential Addons fo…
Improper Authentication vulnerability in WPDeveloper Essential Addons fo…
Improper Authentication vulnerability in WPDeveloper Essential Addons fo…
Improper Authentication vulnerability in WPDeveloper Essential Addons fo…
Improper Authentication vulnerability in WPDeveloper Essential Addons fo…
Improper Authentication vulnerability in WPDeveloper Essential Addons fo…
Improper Authentication vulnerability in WPDeveloper Essential Addons fo…
Detection & mitigation playbook
Vendor / applianceDetect
Inventory every wpdeveloper essential addons for elementor deployment and check each version against the affected-products list above.
Fix
Apply the wpdeveloper essential addons for elementor security patch or hotfix for CVE-2023-32243 on the affected version, following the vendor advisory for your exact build.
Workarounds
Close the privilege gap rather than the entry point: audit which accounts, roles and service identities can reach the affected operation, drop the component to the least privilege it actually needs, and review file and directory permissions created by earlier installs — a default left in place is what makes this reachable. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.
How to detect CVE-2023-32243
A community-maintained Nuclei template exists for this CVE. You can scan for it directly:
nuclei -id cve-2023-32243 -u https://target- Template
- WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset
- Severity
- critical
- Impact
- An attacker can gain unauthorized access to user accounts and potentially take control of the affected WordPress website.
- Remediation
- Update WordPress Elementor Lite plugin to the latest version (5.7.2) or apply the patch provided by the vendor.
Template by ProjectDiscovery nuclei-templates (DhiyaneshDK, Vikas Kundu), MIT licensed. View the full template. Scan only systems you are authorised to test.
Frequently Asked Questions
Is CVE-2023-32243 being exploited in your environment?
Detect and block the exploit chain at execution, on systems you cannot patch yet.