PT-2025-1900 · WordPress · The 140+ Widgets | Xpro Addons For Elementor

Craig Smith

+1

·

Published

2025-01-08

·

Updated

2025-01-08

·

CVE-2024-12584

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress versions up to, and including, 1.4.6.2
Description The issue allows authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts through the "duplicate" function. This enables the exposure of confidential information.
Recommendations For versions up to, and including, 1.4.6.2, consider disabling the duplicate function as a temporary workaround until a patch is available. Restrict access to the plugin to minimize the risk of exploitation, especially for users with Contributor-level access and above.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-12584

Affected Products

The 140+ Widgets | Xpro Addons For Elementor