#VU47501 Improper access control in Elementor Pro - CVE-2020-26596
Published: October 7, 2020 / Updated: October 12, 2020
Elementor Pro
Elementor
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in the Dynamic OOO widget. A remote authenticated attacker can bypass implemented security restrictions and gain unauthorized access to the application, leading to remote code execution.