No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

1 Million WordPress Sites Impacted by Exploited Plugin Vulnerability

May 14, 2023
in Protection
0
Spain Arrests Hackers in Crackdown on Major Criminal Organization


Exploitation of a critical vulnerability in the Essential Addons for Elementor WordPress plugin began immediately after a patch was released, WordPress security firm Defiant warns.

With over one million installations, the Essential Addons for Elementor plugin provides additional elements and extensions for the Elementor website building platform.

Tracked as CVE-2023-32243 (CVSS score of 9.8), the critical-severity vulnerability is described as an unauthenticated privilege escalation that can be exploited to take over any user account.

“It is possible to reset the password of any user as long as we know their username thus being able to reset the password of the administrator and login on their account,” explains Patchstack security researcher Rafie Muhammad, who identified the flaw.

The issue exists in a password reset function that changes the password of any user account without validating a password reset key first.

An unauthenticated attacker could exploit the bug to reset the password of any user account if they know the email or username of that user.

The vulnerability impacts Essential Addons for Elementor versions 5.4.0 to 5.7.1 and was addressed this week with the release of version 5.7.2.

Advertisement. Scroll to continue reading.

The patch adds a check to the password reset function to validate the reset password process.

Muhammad identified and reported the vulnerability on May 8. The first exploitation attempts targeting this bug were observed on May 11, when Essential Addons for Elementor version 5.7.2 was released.

“Wordfence blocked 151 attacks targeting this vulnerability in the past 24 hours,” Defiant notes in an advisory. It’s worth noting that the number of attacks seen by Defiant is rapidly increasing.

Essential Addons for Elementor users are advised to update their installations as soon as possible.

Related: Vulnerability in Field Builder Plugin Exposes Over 2M WordPress Sites to Attacks

Related: Abandoned WordPress Plugin Abused for Backdoor Deployment

Related: Elementor Pro Plugin Vulnerability Exploited to Hack WordPress Websites

Editorial Team

Editorial Team

Related Posts

My Five Favorite Things About the Garmin Forerunner 970 (so Far)
Protection

My Five Favorite Things About the Garmin Forerunner 970 (so Far)

April 4, 2026
The Bowers & Wilkins Px7 S3 Headphones Are 42% Off Right Now
Protection

The Bowers & Wilkins Px7 S3 Headphones Are 42% Off Right Now

April 4, 2026
This Powerful LG 23,500 BTU Smart Air Conditioner Is on Sale for Just $600 Right Now
Protection

This Powerful LG 23,500 BTU Smart Air Conditioner Is on Sale for Just $600 Right Now

April 4, 2026
The CMF Watch 3 Pro With AI-Powered Tracking Is on Sale for $45 Right Now
Protection

The CMF Watch 3 Pro With AI-Powered Tracking Is on Sale for $45 Right Now

April 4, 2026
10 Hacks Every Apple Vision Pro User Should Know
Protection

10 Hacks Every Apple Vision Pro User Should Know

April 4, 2026
Why ‘Open Platform’ Is the Next Big Frontier for Smart Glasses
Protection

Why ‘Open Platform’ Is the Next Big Frontier for Smart Glasses

April 3, 2026
Load More
Next Post
Zelenskyy praises Germany’s €2.7bn military aid pledge to Ukraine

Zelenskyy praises Germany’s €2.7bn military aid pledge to Ukraine

Popular News

  • Bitcoin

    Bitcoin-Gold Correlation Plunges To -0.88, Lowest Since 2022

    0 shares
    Share 0 Tweet 0
  • Coinbase breach fallout spreads, arrest made in India

    0 shares
    Share 0 Tweet 0
  • Exclusive-Prior to Iran attacks, CIA assessed Khamenei would be replaced by IRCG elements if killed, sources say

    0 shares
    Share 0 Tweet 0
  • Current Trends Explained: The Socrates and Skeleton Meme

    0 shares
    Share 0 Tweet 0
  • Blockchain Association Calls For Modernized Crypto Tax Rules In New Release

    0 shares
    Share 0 Tweet 0

Latest News

401(k) balance growth comes with retirement planning pitfalls: advisors

401(k) balance growth comes with retirement planning pitfalls: advisors

April 4, 2026
0

M Swiet Productions | Getty ImagesGregory Hutchison, 72, is living most people's retirement dream. After a nearly 44-year career as...

Ceasefire odds drop sharply amid escalating US-Iran tensions and military strikes: FT

Ceasefire odds drop sharply amid escalating US-Iran tensions and military strikes: FT

April 4, 2026
0

Iran’s call for a permanent ceasefire clashes with rising conflict. Odds for a ceasefire by April 7 have dropped to...

Some central banks have been selling their gold. That doesn’t mean you should too.

Some central banks have been selling their gold. That doesn’t mean you should too.

April 4, 2026
0

Gold suffered its biggest monthly drop in nearly 13 years and some central banks have shifted from being buyers to...

Bitcoin

How Bitcoin ETFs Are Taking A Key Role In Price Discovery And Liquidity – Analyst

April 4, 2026
0

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure The US Bitcoin Spot ETFs are credited...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.