PT-2025-5904 · WordPress · The Builder Shortcode Extras

Francesco Carlucci

·

Published

2025-02-07

·

Updated

2025-02-07

·

CVE-2024-13841

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Builder Shortcode Extras – WordPress Shortcodes Collection to Save You Time plugin for WordPress versions up to, and including, 1.0.0
Description The issue allows authenticated attackers with Contributor-level access and above to extract data from private and draft posts created with Elementor that they should not have access to, due to insufficient restrictions on which posts can be included via the bse-elementor-template shortcode.
Recommendations For versions up to, and including, 1.0.0, consider disabling the bse-elementor-template shortcode until a patch is available to prevent exploitation. Restrict access to private and draft posts created with Elementor to minimize the risk of data exposure.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-13841

Affected Products

The Builder Shortcode Extras