CVE-2024-0900: Elespare – News, Magazine And Blog Addons For Elementor
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
The Elespare – Build Your Blog, News & Magazine Websites with Expert-Designed Template Kits. One Click Import: No Coding Skills Required! plugin for WordPress is vulnerable to unauthorized post creation due to a missing capability check on the elespare_create_post() function hooked via AJAX in all versions up to, and including, 2.1.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary posts.
Affected products
- Elespare Elespare – News, Magazine And Blog Addons For Elementor: up to and including 2.1.2
- WordPress Elespare: version 2.1.2 only
Published 2024-04-23. Last modified 2026-06-17.