WordPress The Pack Elementor addons plugin <= 2.0.8.6 - Local File Inclusion vulnerability
CVE-2024-38768
8.8HIGH
What is CVE-2024-38768?
A Path Traversal vulnerability in The Pack Elementor addons by Webangon permits attackers to exploit improper limitations on pathname restrictions. This flaw enables potential PHP Local File Inclusion, which can allow unauthorized access to sensitive files on the server. The vulnerability affects The Pack Elementor addons versions n/a through 2.0.8.6, posing a significant risk for users failing to implement necessary security measures.
Affected Version(s)
The Pack Elementor addons <= 2.0.8.6