Templines Elementor Helper Core <= 2.7 - Authenticated (Subscriber+) Privilege Escalation
highThe Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.7. This is due to allowing arbitrary user meta updates. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to Administrator...
- CVSS:
- 8.8
- Affected:
- up to 2.7
- Fixed in:
- 2.8
- Disclosed:
- Feb 26, 2025