The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the pae_global_block shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract information from posts that are not public, including drafts, private, password protected, and restricted posts. This applies to posts created with Elementor only.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Feb 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nilambar
Nilambar prime Addons For Elementor |
|
Weaknesses | CWE-639 | |
CPEs | cpe:2.3:a:nilambar:prime_addons_for_elementor:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Nilambar
Nilambar prime Addons For Elementor |
Thu, 20 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Feb 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Prime Addons for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.1 via the pae_global_block shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract information from posts that are not public, including drafts, private, password protected, and restricted posts. This applies to posts created with Elementor only. | |
Title | Prime Addons for Elementor <= 2.0.1 - Authenticated (Contributor+) Insecure Direct Object Reference via pae_global_block Shortcode | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-20T15:14:41.070Z
Reserved: 2025-02-10T20:22:42.489Z
Link: CVE-2024-13855

Updated: 2025-02-20T15:10:05.725Z

Status : Analyzed
Published: 2025-02-20T10:15:11.530
Modified: 2025-02-25T18:23:31.507
Link: CVE-2024-13855

No data.