Vulnerability in 140+ Widgets' Best Addons For Elementor Allows PHP Object Injection
CVE-2024-4471
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 23 May 2024
What is CVE-2024-4471?
The 140+ Widgets plugin for Elementor, developed by Best Addons, is susceptible to a PHP Object Injection vulnerability due to improper handling of untrusted data in the 'export_content' function. Affected versions up to and including 1.4.3.1 permit authenticated attackers with contributor-level permissions to manipulate the system through PHP object injection. While the vulnerable plugin does not contain a prevalent object property (POP) chain, an exploit could arise if additional installed plugins or themes create a POP chain. This scenario could enable attackers to delete arbitrary files, access sensitive information, or execute malicious code, posing significant risks to WordPress environments.
Affected Version(s)
140+ Widgets | Best Addons For Elementor – FREE * <= 1.4.3.1