Elementor Plugin Vulnerable to Local File Inclusion Attacks
CVE-2024-5348
What is CVE-2024-5348?
The Elements For Elementor plugin for WordPress exhibits a Local File Inclusion vulnerability due to improper handling of input parameters in attributes such as 'beforeafter_layout', 'eventsgrid_layout', 'marquee_layout', 'postgrid_layout', 'woocart_layout', and 'woogrid_layout'. This flaw enables authenticated users with Contributor-level access and higher to manipulate file inclusion, potentially executing arbitrary PHP code on the server. Consequences include bypassing access controls, unauthorized data access, and the potential for broader exploits if file uploads are mismanaged, heightening security concerns for environments utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Elements For Elementor * <= 2.1