PT-2024-22980 · WordPress · Essential Addons For Elementor

Ankit Patel

·

Published

2024-04-09

·

Updated

2025-01-08

·

CVE-2024-2974

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress versions up to, and including, 5.9.13
Description The issue allows unauthenticated attackers to extract sensitive data, including private and draft posts, via the load more function. This can lead to sensitive information exposure.
Recommendations For versions up to, and including, 5.9.13, consider disabling the load more function as a temporary workaround until a patch is available. Restrict access to sensitive data to minimize the risk of exploitation.

Fix

Information Disclosure

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2024-2974

Affected Products

Essential Addons For Elementor