PT-2025-9071 · WordPress · Ultra Addons Lite For Elementor

Francesco Carlucci

·

Published

2025-02-28

·

Updated

2025-02-28

·

CVE-2024-13832

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ultra Addons Lite for Elementor plugin for WordPress versions up to, and including, 1.1.8
Description The issue allows authenticated attackers with Contributor-level access and above to extract data from password-protected, private, or draft posts via the 'ut elementor' shortcode, due to insufficient restrictions on which posts can be included.
Recommendations For Ultra Addons Lite for Elementor plugin for WordPress versions up to, and including, 1.1.8, consider updating to a version that addresses the insufficient restrictions on post inclusion to prevent unauthorized data exposure.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2024-13832

Affected Products

Ultra Addons Lite For Elementor