Arbitrary File Inclusion Vulnerability in WPZOOM Addons for Elementor
CVE-2024-5147

9.8CRITICAL

What is CVE-2024-5147?

The WPZOOM Addons for Elementor plugin for WordPress is susceptible to a Local File Inclusion vulnerability due to improper handling of the 'grid_style' parameter. This security flaw allows unauthenticated attackers to include and execute arbitrary files on the server, thereby executing malicious PHP code contained within those files. As a result, attackers could potentially circumvent access controls, access sensitive information, or execute unauthorized code especially through uploads of images or other seemingly harmless file types.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

WPZOOM Addons for Elementor (Templates, Widgets) * <= 1.1.37

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Craig Smith
.