Arbitrary Location Query Vulnerability in ElementsKit PRO Plugin
CVE-2024-4404

9.6CRITICAL

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
14 June 2024

Summary

The ElementsKit PRO plugin for WordPress is affected by a vulnerability that permits Server-Side Request Forgery (SSRF). This issue arises through the 'render_raw' function, which can be exploited by authenticated users with contributor-level access or higher. Attackers can leverage this vulnerability to send requests to arbitrary locations, potentially exposing sensitive data or modifying information from internal services while bypassing security controls.

Affected Version(s)

ElementsKit Pro * <= 3.6.2

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ngô Thiên An
.