PT-2024-17445 · WordPress · Gold Addons For Elementor

Brokenac Ignore

·

Published

2024-12-06

·

Updated

2024-12-06

·

CVE-2024-12110

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Gold Addons for Elementor plugin for WordPress versions up to, and including, 1.3.2
Description The issue allows unauthorized modification of data due to a missing capability check on the activate() and deactivate() functions. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate and deactivate licenses.
Recommendations For Gold Addons for Elementor plugin for WordPress versions up to, and including, 1.3.2: Update the plugin to a version that includes the necessary capability checks for the activate() and deactivate() functions. As a temporary workaround, consider restricting access to the activate() and deactivate() functions to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-12110

Affected Products

Gold Addons For Elementor