CVE Vulnerabilities

CVE-2016-11003

Improper Privilege Management

Published: Sep 20, 2019 | Modified: Feb 04, 2026
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
BloomElegantthemes*1.1.1 (excluding)

Potential Mitigations

References