PT-2024-16472 · WordPress · Ultraaddons

Francesco Carlucci

·

Published

2024-11-20

·

Updated

2024-11-21

·

CVE-2024-10696

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions UltraAddons – Elementor Addons plugin for WordPress versions up to, and including, 1.1.8
Description The issue allows authenticated attackers with Contributor-level access and above to expose the contents of draft, private, and pending posts due to missing validation on a user-controlled key in the show template endpoint.
Recommendations For versions up to, and including, 1.1.8, update to a version that includes the necessary validation to prevent Insecure Direct Object Reference. As a temporary workaround, consider restricting access to the show template endpoint to minimize the risk of exploitation.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10696

Affected Products

Ultraaddons