CVE-2024-35674: WordPress Unlimited Elements For Elementor plugin <= 1.5.109 - Broken Access Control vulnerability
Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through <= 1.5.109.
Security readout for executives and security teams
Plain-English summary
This is a broken access control flaw in the WordPress Unlimited Elements For Elementor plugin through version 1.5.109. A logged-in low-privilege user may access information they should not. The cited record rates impact as medium, with confidentiality impact only and no integrity or availability impact stated.
Executive priority
Treat as a scheduled remediation item, not an emergency, unless affected sites allow broad user registration or untrusted logins. Prioritize confirming whether the plugin is deployed, then update based on vendor guidance.
Technical view
CVE-2024-35674 is CWE-862 Missing Authorization in package unlimited-elements-for-elementor. CVSS 3.1 is 4.3: network reachable, low attack complexity, low privileges required, no user interaction, unchanged scope, low confidentiality impact, no integrity or availability impact. The sources do not identify the exact vulnerable endpoint or data exposed.
Likely exposure
Exposure is limited to WordPress sites running Unlimited Elements For Elementor at version 1.5.109 or earlier. Risk is higher where untrusted users can create or hold low-privilege WordPress accounts. Sites without this plugin, or with versions outside the affected range, are not shown as affected by the provided sources.
Exploitation context
The provided sources do not report active exploitation, and the CVE is not listed as KEV in the bundle. The CVSS vector indicates remote exploitation is possible by a low-privilege authenticated user without user interaction. No public exploit details are included in the supplied evidence.
Researcher notes
Evidence is limited to the CVE and Patchstack database references. The source bundle does not describe the vulnerable function, endpoint, authorization check, exploit status, or fixed version. Validation should avoid assumptions beyond plugin presence, affected version range, and authenticated low-privilege exposure.
Mitigation direction
Inventory WordPress sites for the Unlimited Elements For Elementor plugin and installed version.
If version is 1.5.109 or earlier, check vendor or Patchstack guidance for the fixed release.
Update only to a vendor-confirmed fixed version, following normal WordPress change control.
Restrict or review low-privilege WordPress accounts until remediation is complete.
Disable the plugin if it is unnecessary and business impact is acceptable.
Validation and detection
Confirm plugin presence and exact version on every managed WordPress site.
Check whether public or untrusted user registration is enabled on affected sites.
Review WordPress users with low-privilege roles for unnecessary access.
After remediation, verify the affected plugin version is no longer deployed.
Record exceptions where vendor guidance or patch availability is still unclear.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-862: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.