PT-2024-16469 · Unknown+1 · Skt Addons For Elementor+1

Francesco Carlucci

·

Published

2024-11-08

·

Updated

2024-11-13

·

CVE-2024-10693

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SKT Addons for Elementor versions up to, and including, 3.3
Description The issue allows authenticated attackers with Contributor-level access and above to extract data from private or draft posts created by Elementor that they should not have access to, due to insufficient restrictions on which posts can be included via the Unfold widget.
Recommendations For SKT Addons for Elementor versions up to, and including, 3.3, update to the latest version immediately to mitigate risks. As a temporary workaround, consider restricting access to the Unfold widget until a patch is available.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-10693

Affected Products

Elementor
Skt Addons For Elementor