PT-2024-39950 · WordPress · Pdf Generator Addon For Elementor Page Builder

Matthew Rollings

+1

·

Published

2024-11-15

·

Updated

2024-12-23

·

CVE-2024-9935

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PDF Generator Addon for Elementor Page Builder plugin for WordPress versions up to, and including, 1.7.5
Description The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The vulnerability is exploited via the rtw pgaepb dwnld pdf() function.
Recommendations For versions up to, and including, 1.7.5, update to a version that contains a fix for this issue. As a temporary workaround, consider disabling the rtw pgaepb dwnld pdf() function until a patch is available. Restrict access to sensitive files on the server to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-9935

Affected Products

Pdf Generator Addon For Elementor Page Builder