PT-2024-17999 · WordPress · Happy Addons For Elementor

Lucio Sá

·

Published

2024-04-09

·

Updated

2025-01-07

·

CVE-2024-1387

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Happy Addons for Elementor plugin for WordPress versions up to, and including, 3.10.4
Description The issue is related to insufficient authorization on the duplicate thing() function, allowing attackers with contributor-level access and above to clone arbitrary posts, including private and password-protected ones, which may lead to information exposure.
Recommendations For versions up to, and including, 3.10.4, update to a version higher than 3.10.4 to resolve the issue. As a temporary workaround, consider disabling the duplicate thing() function until a patch is available.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-1387

Affected Products

Happy Addons For Elementor