PT-2024-37641 · WordPress · Elementskit Elementor Addons
Matthew Rollings
+1
·
Published
2024-07-18
·
Updated
2025-01-16
·
CVE-2024-6455
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ElementsKit Elementor addons plugin for WordPress versions up to, and including, 3.2.0
Description
The issue allows unauthenticated attackers to view any item created in Elementor, including posts, pages, and templates, such as drafts, pending, and private items, due to missing capability checks on the
ekit widgetarea content function.Recommendations
For versions up to, and including, 3.2.0, update to a version that includes the necessary capability checks for the
ekit widgetarea content function to prevent information exposure.
As a temporary workaround, consider restricting access to the ekit widgetarea content function until a patch is available.Fix
Missing Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elementskit Elementor Addons