Improper Privilege Management in IdeaBox PowerPack Pro for Elementor
CVE-2024-39634

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 August 2024

What is CVE-2024-39634?

An improper privilege management vulnerability exists in the IdeaBox PowerPack Pro for Elementor plugin, which could allow attackers to escalate privileges. This flaw affects versions from n/a up to 2.10.14, enabling unauthorized users to potentially gain elevated access and manipulate the system beyond their intended capabilities. Website administrators using this plugin should assess their installations and apply necessary updates to safeguard against potential exploitation.

Affected Version(s)

PowerPack Pro for Elementor <= 2.10.14

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.