
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24605 is a Missing Authorization vulnerability in the X Addons for Elementor WordPress plugin developed by pencilwp. It allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. The vulnerability affects all versions of the plugin from n/a through 1.0.23. It was published on January 23, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (NVD, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before allowing access to certain functionality. The attack vector is network-based, requires low privileges (any authenticated WordPress user), and no user interaction. An attacker can send crafted requests to plugin endpoints that lack proper capability checks, thereby accessing or triggering functionality beyond their intended authorization level (NVD, Patchstack).
Successful exploitation results in a limited confidentiality impact — an authenticated low-privileged user can access information or functionality they should not be authorized to use. Integrity and availability are not directly impacted according to the CVSS assessment. The scope is limited to the affected WordPress installation, with no evidence of lateral movement potential beyond the plugin's functionality (NVD).
The vulnerability requires the attacker to be authenticated with at least a low-privilege account on the target WordPress site, limiting opportunistic mass exploitation. The EPSS score is very low at 0.000080 (approximately 0.008%), indicating a low probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation, no known public proof-of-concept exploit code, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (NVD).
current_user_can() or nonce capability checks./wp-admin/admin-ajax.php) with actions associated with X Addons for Elementor.wp-admin/admin-ajax.php with plugin-specific action parameters from accounts that do not normally interact with Elementor plugin settings.Users should update the X Addons for Elementor plugin to a version above 1.0.23 that includes the authorization fix. If an updated version is not yet available, site administrators should consider deactivating the plugin until a patch is released. Additionally, restricting user registration and limiting low-privilege account creation on the WordPress site reduces the attack surface (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."