Arbitrary Location Query Vulnerability in ElementsKit PRO Plugin
CVE-2024-4404
9.6CRITICAL
Summary
The ElementsKit PRO plugin for WordPress is affected by a vulnerability that permits Server-Side Request Forgery (SSRF). This issue arises through the 'render_raw' function, which can be exploited by authenticated users with contributor-level access or higher. Attackers can leverage this vulnerability to send requests to arbitrary locations, potentially exposing sensitive data or modifying information from internal services while bypassing security controls.
Affected Version(s)
ElementsKit Pro * <= 3.6.2
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ngô Thiên An