All CVEs — page 85 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
A Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows attackers to forge requests that the victim has authorized, potentially leading to unauthorized actions on the victim's behalf.
The flaw allows unauthenticated attackers to escalate privileges by exploiting a missing permission enforcement and a lack of key allowlist, leading to the ability to register an account with administrator role and gain full administrative access.