Arbitrary Location Query Vulnerability in ElementsKit PRO Plugin
CVE-2024-4404
8.5HIGH
What is CVE-2024-4404?
The ElementsKit PRO plugin for WordPress is affected by a vulnerability that permits Server-Side Request Forgery (SSRF). This issue arises through the 'render_raw' function, which can be exploited by authenticated users with contributor-level access or higher. Attackers can leverage this vulnerability to send requests to arbitrary locations, potentially exposing sensitive data or modifying information from internal services while bypassing security controls.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ElementsKit Pro * <= 3.6.2