PHP Remote File Inclusion vulnerability in Pricing table addon for Elementor
CVE-2024-52499
7.5HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 28 November 2024
Summary
The Kardi Pricing Table Addon for Elementor contains a vulnerability that grants malicious actors the ability to exploit PHP Local File Inclusion due to improper control in the handling of filename parameters. This flaw can result in unauthorized access to sensitive files on the server, potentially leading to further compromises of the application. Affected versions range from n/a through 1.0.0. It is essential for users to update to secure versions and implement security measures to mitigate the risk associated with this vulnerability.
Affected Version(s)
Pricing table addon for elementor <= 1.0.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro Soares de Alcântara - Kinorth (Patchstack Alliance)