CVE-2023-3124

Elementor Pro <= 3.11.6 - Authenticated(Subscriber+) Privilege Escalation via update_page_option

The Elementor Pro plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check on the update_page_option function in versions up to, and including, 3.11.6. This makes it possible for authenticated attackers with subscriber-level capabilities to update arbitrary site options, which can lead to privilege escalation.


We have discovered 156,255 live websites that are affected by CVE-2023-3124.

Run a Free Instant Scan




Affected Software

Product  Elementor Pro
Category Landing Page Builders
Vulnerable Domains156,255 live websites (12% of Elementor Pro install base)
Vulnerable Versions
  • from 0 through 3.11.6
Vulnerable Versions Count158 versions ( 59% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jun 7, 2023
  • Updated - Apr 8, 2026

Credits

  • Jerome Bruandet (finder)

Website Distribution by Country

Number of websites using CVE-2023-3124
United States34,631 websites



Germany14,430 websites
Brazil8,683 websites
France7,737 websites
Russia6,833 websites
GB6,402 websites
Italy6,115 websites
Spain5,800 websites
Poland4,614 websites
Israel4,178 websites

Website Distribution by TLD

Number of websites using CVE-2023-3124
.com58,677 websites
.com.br8,131 websites
.de8,023 websites
.ru5,452 websites
.org4,995 websites
.it4,345 websites
.co.uk3,473 websites
.pl3,469 websites
.fr3,129 websites
.nl3,110 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-3124

Top websites that are affected by CVE-2023-3124. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.de Germany***
******.com United States*,***
**********.com United States*,***
**********.com United States*,***
***************.org United States*,***
**********************.de Germany**,***
************.com South Africa**,***
****.ru Russia**,***
********************.com United States**,***
******.com United States**,***
See full domain list

FAQ

CVE-2023-3124 is Missing Authorization in Elementor Pro
A total of 156,255 websites have been identified as vulnerable to CVE-2023-3124, based on global website indexing conducted by WebTechSurvey.
The Elementor Pro is affected by the CVE-2023-3124 vulnerability.
Elementor Pro versions up to and including 3.11.6 are vulnerable to CVE-2023-3124.