Information Exposure Vulnerability in Ultra Addons Lite for Elementor by WordPress
CVE-2024-13832
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 February 2025
What is CVE-2024-13832?
The Ultra Addons Lite for Elementor plugin for WordPress contains a security flaw that allows authenticated users with Contributor-level access or higher to exploit the 'ut_elementor' shortcode. Due to insufficient restrictions on accessible posts, these users can potentially retrieve sensitive data from password-protected, private, or draft posts, violating user privacy and data integrity. This vulnerability underscores the importance of stringent access controls and regular security audits for plugins.
Affected Version(s)
Ultra Addons Lite for Elementor * <= 1.1.8