WPKoi Templates for Elementor <= 3.7.3 - Authenticated (Contributor+) Insecure Direct Object Reference to Sensitive Information Exposure via Template Import

Medium 4.3 CWE-639Fixed in 3.7.4
ID
WPSEC-2026-0763
Plugin
WPKoi Templates for Elementor (wpkoi-templates-for-elementor)
Affected
all versions before 3.7.4
Remediation
Update to 3.7.4 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-11
Attack surface
WPKoi Templates for Elementor on WPSec AttackSurface
Fix released
Published

Description

The WPKoi Templates for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'wtfe_update_page_meta_ajax' AJAX action in all versions up to, and including, 3.7.3. This is due to missing validation that the user-supplied source 'template_id' is an Elementor template the user is permitted to edit. This makes it possible for authenticated attackers, with contributor-level access and above, to copy the Elementor content and page settings of arbitrary posts, including private and draft posts by other users, into a post they can edit and so read it.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0