PHP Remote File Inclusion vulnerability in Pricing table addon for Elementor
CVE-2024-52499
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 November 2024
What is CVE-2024-52499?
The Kardi Pricing Table Addon for Elementor contains a vulnerability that grants malicious actors the ability to exploit PHP Local File Inclusion due to improper control in the handling of filename parameters. This flaw can result in unauthorized access to sensitive files on the server, potentially leading to further compromises of the application. Affected versions range from n/a through 1.0.0. It is essential for users to update to secure versions and implement security measures to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Pricing table addon for elementor <= 1.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved