PT-2024-26287 · WordPress · Elementskit Pro

Craig Smith

+1

·

Published

2024-05-02

·

Updated

2025-01-08

·

CVE-2024-3500

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ElementsKit Pro plugin for WordPress versions up to, and including, 3.6.0
Description The issue allows authenticated attackers with contributor-level access and above to include and execute arbitrary files on the server. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The vulnerability is exploited via the Price Menu, Hotspot, and Advanced Toggle widgets.
Recommendations For versions up to, and including, 3.6.0, update to a version that contains a fix for this issue to prevent Local File Inclusion attacks. As a temporary workaround, consider restricting access to the Price Menu, Hotspot, and Advanced Toggle widgets to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-3500

Affected Products

Elementskit Pro