Premium Addons for Elementor <= 4.10.31 - Missing Authorization to Information Disclosure
Published May 31, 2024
4.3
MEDIUMCVSS 3.1
EPSS 0.34%
Description
The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_template_content() function in all versions up to, and including, 4.10.31. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve Elementor template data.
Affected products
- Vendor Leap13 Product Premium Addons for Elementor – Powerful Elementor Templates & Widgets Defaultunaffected
Affected
- ≥ 0, ≤ 4.10.31
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Leap13 | Premium Addons for Elementor – Powerful Elementor Templates & Widgets | unaffected | Affected
|
- < 4.10.32
-
Affected
- ≥ 0, ≤ 4.10.31
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Leap13 | Premium Addons for Elementor | unaffected | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32759 Advisory
- https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/tags/4.10.28/includes/addons-integration.php#L1408 Product
- https://plugins.trac.wordpress.org/changeset/3090037/premium-addons-for-elementor/trunk/includes/addons-integration.php Patch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/175cb977-dcba-429f-814c-6de078e23472?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data