PT-2024-16215 · Unknown · Elementsready Addons For Elementor
Ankit Patel
·
Published
2024-12-17
·
Updated
2024-12-19
·
CVE-2024-10356
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ElementsReady Addons for Elementor versions up to, and including, 6.4.8
Description
The issue allows authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data due to Sensitive Information Exposure in the inc/Widgets/accordion/output/content.php file.
Recommendations
For versions up to, and including, 6.4.8, update to a version later than 6.4.8 to resolve the issue.
As a temporary workaround, consider restricting access to the inc/Widgets/accordion/output/content.php file until a patch is available.
Restrict Contributor-level access and above to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elementsready Addons For Elementor