Information Exposure Vulnerability in Unlimited Theme Addon for Elementor and WooCommerce
CVE-2024-12116

4.3MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
11 January 2025

Summary

The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is susceptible to an information exposure issue through the 'uta-template' shortcode. This vulnerability arises from inadequate access controls which fail to restrict the visibility of private or draft posts created with Elementor. Authenticated users with Contributor-level access and above may exploit this weakness to gain unauthorized access to sensitive content that should remain private, potentially compromising data integrity and confidentiality.

Affected Version(s)

Unlimited Theme Addon For Elementor and WooCommerce * <= 1.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.