CVE-2026-24605
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24605 is a Missing Authorization vulnerability in the X Addons for Elementor WordPress plugin developed by pencilwp. It allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. The vulnerability affects all versions of the plugin from n/a through 1.0.23. It was published on January 23, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (NVD, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before allowing access to certain functionality. The attack vector is network-based, requires low privileges (any authenticated WordPress user), and no user interaction. An attacker can send crafted requests to plugin endpoints that lack proper capability checks, thereby accessing or triggering functionality beyond their intended authorization level (NVD, Patchstack).

Impact

Successful exploitation results in a limited confidentiality impact — an authenticated low-privileged user can access information or functionality they should not be authorized to use. Integrity and availability are not directly impacted according to the CVSS assessment. The scope is limited to the affected WordPress installation, with no evidence of lateral movement potential beyond the plugin's functionality (NVD).

Exploitability

The vulnerability requires the attacker to be authenticated with at least a low-privilege account on the target WordPress site, limiting opportunistic mass exploitation. The EPSS score is very low at 0.000080 (approximately 0.008%), indicating a low probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation, no known public proof-of-concept exploit code, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (NVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the X Addons for Elementor plugin (version ≤ 1.0.23) using tools like WPScan or by inspecting plugin directories.
  2. Obtain low-privilege access: Register or obtain credentials for a low-privilege WordPress account (e.g., Subscriber role) on the target site.
  3. Identify unprotected endpoints: Enumerate AJAX actions or REST API endpoints registered by the plugin that lack proper current_user_can() or nonce capability checks.
  4. Send crafted request: Issue an authenticated HTTP request (with valid WordPress authentication cookies) to the identified endpoint, bypassing the missing authorization check.
  5. Access restricted data or functionality: Retrieve sensitive information or trigger plugin functionality that should be restricted to higher-privileged users (NVD, Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated low-privilege users making repeated or unusual requests to plugin-specific AJAX endpoints (/wp-admin/admin-ajax.php) with actions associated with X Addons for Elementor.
  • Logs: Unexpected access patterns from subscriber-level accounts to administrative or restricted plugin functionality in WordPress debug logs.
  • Network: Unusual POST requests to wp-admin/admin-ajax.php with plugin-specific action parameters from accounts that do not normally interact with Elementor plugin settings.

Mitigation and workarounds

Users should update the X Addons for Elementor plugin to a version above 1.0.23 that includes the authorization fix. If an updated version is not yet available, site administrators should consider deactivating the plugin until a patch is released. Additionally, restricting user registration and limiting low-privilege account creation on the WordPress site reduces the attack surface (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management