Information Exposure Vulnerability in Unlimited Theme Addon for Elementor and WooCommerce
CVE-2024-12116
4.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 11 January 2025
Summary
The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is susceptible to an information exposure issue through the 'uta-template' shortcode. This vulnerability arises from inadequate access controls which fail to restrict the visibility of private or draft posts created with Elementor. Authenticated users with Contributor-level access and above may exploit this weakness to gain unauthorized access to sensitive content that should remain private, potentially compromising data integrity and confidentiality.
Affected Version(s)
Unlimited Theme Addon For Elementor and WooCommerce * <= 1.2.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Francesco Carlucci