PHP Remote File Inclusion vulnerability in Pricing table addon for Elementor
CVE-2024-52499

7.5HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
28 November 2024

Summary

The Kardi Pricing Table Addon for Elementor contains a vulnerability that grants malicious actors the ability to exploit PHP Local File Inclusion due to improper control in the handling of filename parameters. This flaw can result in unauthorized access to sensitive files on the server, potentially leading to further compromises of the application. Affected versions range from n/a through 1.0.0. It is essential for users to update to secure versions and implement security measures to mitigate the risk associated with this vulnerability.

Affected Version(s)

Pricing table addon for elementor <= 1.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro Soares de Alcântara - Kinorth (Patchstack Alliance)
.
CVE-2024-52499 : PHP Remote File Inclusion vulnerability in Pricing table addon for Elementor | SecurityVulnerability.io