The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, draft, or scheduled posts that they should not have access to by duplicating the post.
History

Mon, 24 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Detheme
Detheme dethemekit For Elementor
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:detheme:dethemekit_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Detheme
Detheme dethemekit For Elementor

Thu, 13 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 07:15:00 +0000

Type Values Removed Values Added
Description The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, draft, or scheduled posts that they should not have access to by duplicating the post.
Title DethemeKit For Elementor <= 2.1.8 - Authenticated (Contributor+) Protected Post Disclosure
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-02-13T14:52:26.806Z

Reserved: 2025-01-23T01:19:54.957Z

Link: CVE-2025-0661

cve-icon Vulnrichment

Updated: 2025-02-13T14:52:22.687Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-13T07:15:10.777

Modified: 2025-02-24T17:10:16.007

Link: CVE-2025-0661

cve-icon Redhat

No data.