The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, pending and private items.
History

Thu, 16 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpmet
Wpmet elements Kit Elementor Addons
Weaknesses CWE-862
CPEs cpe:2.3:a:wpmet:elements_kit_elementor_addons:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpmet
Wpmet elements Kit Elementor Addons

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-09T19:11:27.770Z

Reserved: 2024-07-02T17:12:37.129Z

Link: CVE-2024-6455

cve-icon Vulnrichment

Updated: 2024-08-01T21:41:03.300Z

cve-icon NVD

Status : Analyzed

Published: 2024-07-18T21:15:02.683

Modified: 2025-01-16T15:06:56.973

Link: CVE-2024-6455

cve-icon Redhat

No data.