A security vulnerability has been disclosed in the popular WordPress plugin Essential Addons for Elementor that could be exploited to gain elevated privileges on affected sites.
The flaw, tracked as CVE-2023-32243, was addressed by the plugin's maintainers in version 5.7.2, released on 11 May 2023. Essential Addons for Elementor has more than one million active installations.
Patchstack researcher Rafie Muhammad said: “This plugin has an unauthenticated privilege escalation vulnerability and allows any unauthenticated user to escalate their privileges to those of any user on the WordPress site.”
Successful exploitation of the vulnerability could allow a threat actor to reset the password of any arbitrary user, provided the malicious party knows that user's username. The flaw is believed to have existed since version 5.4.0.
This can have serious consequences, because the vulnerability can be weaponized to reset the password associated with an administrator account and take full control of the site.
“The vulnerability arises because this password reset function does not validate the password reset key and instead directly changes the password of a given user,” Muhammad pointed out.
The disclosure comes more than a year after Patchstack revealed another critical vulnerability in the same plugin that could have been abused to execute arbitrary code on compromised sites.
The findings also follow the discovery of a new wave of attacks on WordPress sites since late March 2023, aimed at injecting the notorious SocGholish malware (also known as FakeUpdates).
SocGholish is a JavaScript-based malware framework that continuously operates as an initial-access broker, facilitating the delivery of additional malware to infected servers. The malware has been distributed through drive-by downloads disguised as a web browser update.
The latest campaign, discovered by Sucuri, was found to use compression techniques based on a software library called zlib to obfuscate the malware, reduce its footprint and evade detection.
Sucuri researcher Denis Sinegubko said: “Bad actors constantly evolve their tactics, techniques and procedures to avoid detection and extend the lifespan of their malware campaigns.”
“The SocGholish malware is a prime example of this, as attackers have previously changed their approach in order to inject malicious scripts into compromised WordPress sites.”
It is not just SocGholish. In a technical report this week, Malwarebytes detailed a malvertising campaign targeting visitors to adult websites with pop-up ads mimicking fake Windows updates, used to drop the “in2al5d p3in4er” loader (also known as Invalid Printer).

Jérôme Segura, director of threat intelligence at Malwarebytes, said: “The program is very well designed, because it relies on the web browser to display a full-screen animation that closely resembles what you would expect from Microsoft.”
The loader, documented by Morphisec last month, is designed to inspect the system's graphics card to determine whether it is running in a virtual machine or a sandbox environment, and ultimately to launch the Aurora information stealer.
According to Malwarebytes, the campaign has claimed 585 confirmed victims over the past two months, and the threat actor is also linked to other tech-support scams and to the Amadey bot command-and-control panel.
Essential Addons for Elementor plugin vulnerability actively exploited
In its own advisory, Wordfence reported that a critical vulnerability in the Essential Addons for Elementor plugin is being actively exploited, and that it blocked 200 attacks targeting the vulnerability in the past 24 hours, making it essential for users to update to the latest version as soon as possible.