PT-2024-23230 · WordPress · Essential Addons For Elementor

Ancorn

+1

·

Published

2024-03-30

·

Updated

2025-01-08

·

CVE-2024-3018

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Essential Addons for Elementor plugin for WordPress versions up to, and including, 5.9.13
Description The issue allows authenticated attackers with author-level access and above to inject a PHP Object via deserialization of untrusted input from the error resetpassword attribute of the "Login | Register Form" widget. If a POP chain is present via an additional plugin or theme, it could enable the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
Recommendations For versions up to, and including, 5.9.13, update to a version that contains a fix for this issue to prevent PHP Object Injection. As a temporary workaround, consider disabling the "Login | Register Form" widget until a patch is available. Restrict access to the error resetpassword attribute to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-3018

Affected Products

Essential Addons For Elementor