PT-2022-9522 · WordPress · The Plus Addons For Elementor

Nicolas Vidal

·

Published

2022-01-10

·

Updated

2022-10-25

·

CVE-2021-24948

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Plus Addons for Elementor - Pro WordPress plugin versions prior to 5.0.7
Description The issue concerns the lack of validation for the qvquery parameter in the tp get dl post info ajax AJAX action. This could potentially allow unauthenticated users to access sensitive information, including private and draft posts.
Recommendations For versions prior to 5.0.7, update to version 5.0.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the tp get dl post info ajax AJAX action to prevent unauthenticated users from exploiting the lack of validation for the qvquery parameter.

Exploit

Fix

Information Disclosure

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2021-24948

Affected Products

The Plus Addons For Elementor