The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, pending and private items.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Jan 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wpmet
Wpmet elements Kit Elementor Addons |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:wpmet:elements_kit_elementor_addons:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wpmet
Wpmet elements Kit Elementor Addons |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-09T19:11:27.770Z
Reserved: 2024-07-02T17:12:37.129Z
Link: CVE-2024-6455

Updated: 2024-08-01T21:41:03.300Z

Status : Analyzed
Published: 2024-07-18T21:15:02.683
Modified: 2025-01-16T15:06:56.973
Link: CVE-2024-6455

No data.