Description
WordPress Plugin PowerPack Pro for Elementor is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin PowerPack Pro for Elementor version 2.10.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.10.15 or latest
References
Related Vulnerabilities
WordPress Plugin Themify Portfolio Post Cross-Site Scripting (1.2.1)
MySQL CVE-2020-14809 Vulnerability (CVE-2020-14809)
WordPress Plugin Wordable Security Bypass (3.1.1)
Varnish Cache Reachable Assertion Vulnerability (CVE-2019-15892)
WordPress Plugin WordPress Download Manager Cross-Site Scripting (3.2.21)