Vulnerability in 140+ Widgets' Best Addons For Elementor Allows PHP Object Injection
CVE-2024-4471

8HIGH

What is CVE-2024-4471?

The 140+ Widgets plugin for Elementor, developed by Best Addons, is susceptible to a PHP Object Injection vulnerability due to improper handling of untrusted data in the 'export_content' function. Affected versions up to and including 1.4.3.1 permit authenticated attackers with contributor-level permissions to manipulate the system through PHP object injection. While the vulnerable plugin does not contain a prevalent object property (POP) chain, an exploit could arise if additional installed plugins or themes create a POP chain. This scenario could enable attackers to delete arbitrary files, access sensitive information, or execute malicious code, posing significant risks to WordPress environments.

Affected Version(s)

140+ Widgets | Best Addons For Elementor – FREE * <= 1.4.3.1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Francesco Carlucci
.