Local File Inclusion Vulnerability in Responsive Addons for Elementor Plugin from WordPress
CVE-2024-13353
8.8HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 21 February 2025
Summary
The Responsive Addons for Elementor plugin for WordPress is susceptible to a Local File Inclusion vulnerability. This flaw allows authenticated users with Contributor-level access or higher to include and potentially execute arbitrary files on the server. By exploiting this vulnerability, attackers could bypass access controls, access sensitive information, or execute malicious PHP code using ‘safe’ file types such as images. As a result, it poses considerable risk to the security and integrity of affected WordPress sites.
Affected Version(s)
Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates * <= 1.6.4
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Matthew Rollings