PT-2024-22952 · WordPress · Element Pack Elementor Addons

Krzysztof Zając

·

Published

2024-04-11

·

Updated

2025-01-21

·

CVE-2024-2966

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Element Pack Elementor Addons plugin for WordPress versions up to, and including, 5.5.6
Description The issue allows unauthenticated attackers to extract sensitive data, including password-protected post details, via the element pack ajax search function. This makes sensitive information exposure possible.
Recommendations For versions up to, and including, 5.5.6, consider disabling the element pack ajax search function as a temporary workaround until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-2966

Affected Products

Element Pack Elementor Addons