The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.8 via the show_template due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to expose the contents of draft, private, and pending posts.
History

Wed, 05 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Codeastrology
Codeastrology ultraaddons
CPEs cpe:2.3:a:codeastrology:ultraaddons:*:*:*:*:*:*:*:*
Vendors & Products Codeastrology
Codeastrology ultraaddons

Thu, 21 Nov 2024 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 21 Nov 2024 02:45:00 +0000

Type Values Removed Values Added
Description The UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.8 via the show_template due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to expose the contents of draft, private, and pending posts.
Title UltraAddons – Elementor Addons (Header Footer Builder, Custom Font, Custom CSS,Woo Widget, Menu Builder, Anywhere Elementor Shortcode) <= 1.1.8 - Insecure Direct Object Reference to Sensitive Information Exposure via UA_Template Shortcode
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-11-21T11:40:11.365Z

Reserved: 2024-11-01T16:48:38.589Z

Link: CVE-2024-10696

cve-icon Vulnrichment

Updated: 2024-11-21T11:34:53.225Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-21T11:15:21.087

Modified: 2025-02-05T14:55:34.007

Link: CVE-2024-10696

cve-icon Redhat

No data.