Data Exposure Vulnerability in Element Pack Elementor Addons Plugin for WordPress
CVE-2024-11852
4.3MEDIUM
What is CVE-2024-11852?
CVE-2024-11852 identifies a critical data exposure vulnerability within the Element Pack Elementor Addons plugin for WordPress. The issue arises from a missing capability check in the get_layouts() function, affecting all versions up to and including 5.10.12. This vulnerability enables authenticated attackers, including users with Subscriber-level access, to exploit the weakness by gaining unauthorized access to sensitive data. As a result, these attackers can retrieve detailed listings of layout templates, potentially compromising the security of the WordPress site. Website administrators are advised to patch this vulnerability immediately to secure their sites.