The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.3 via the Unfold widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Mar 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sktthemes
Sktthemes skt Addons For Elementor |
|
CPEs | cpe:2.3:a:sktthemes:skt_addons_for_elementor:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Sktthemes
Sktthemes skt Addons For Elementor |
Mon, 11 Nov 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 09 Nov 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.3 via the Unfold widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to. | |
Title | SKT Addons for Elementor <= 3.3 - Authenticated (Contributor+) Post Disclosure | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-11-11T11:56:52.669Z
Reserved: 2024-11-01T16:12:16.559Z
Link: CVE-2024-10693

Updated: 2024-11-11T11:56:39.991Z

Status : Analyzed
Published: 2024-11-09T04:15:04.943
Modified: 2025-03-06T14:25:09.843
Link: CVE-2024-10693

No data.