Private Post Data Exposed through Unfold Widget
CVE-2024-10693
4.3MEDIUM
Summary
The SKT Addons for Elementor plugin for WordPress is affected by a vulnerability that allows authenticated users with Contributor-level access or above to gain unauthorized access to sensitive information. This occurs through the Unfold widget, where insufficient restrictions permit these users to access private or draft posts created using Elementor. As a result, sensitive content may be exposed to users who should not have access, leading to potential data leaks and privacy concerns for site owners relying on the Elementor platform.
Affected Version(s)
SKT Addons for Elementor * <= 3.3
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francesco Carlucci