PT-2025-1748 · WordPress · Typer Core

Francesco Carlucci

·

Published

2025-01-30

·

Updated

2025-01-31

·

CVE-2024-12102

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Typer Core plugin for WordPress versions up to, and including, 1.9.6
Description The issue concerns insufficient restrictions on which posts can be included through the 'elementor-template' shortcode, allowing authenticated attackers with Contributor-level access and above to extract data from private or draft posts created by Elementor that they should not have access to.
Recommendations For versions up to, and including, 1.9.6, consider disabling the 'elementor-template' shortcode until a patch is available to prevent potential data exposure. Restrict access to private or draft posts created by Elementor to minimize the risk of exploitation.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-12102

Affected Products

Typer Core