Arbitrary File Inclusion Vulnerability in Plus Addons for Elementor Page Builder
CVE-2024-5455
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 21 June 2024
Summary
The Plus Addons for Elementor Page Builder plugin for WordPress is susceptible to Local File Inclusion (LFI) vulnerabilities across all versions up to and including 5.5.4. The vulnerability leverages the 'magazine_style' parameter within the Dynamic Smart Showcase widget, permitting authenticated attackers with Contributor-level access or higher to include and execute arbitrary files on the server. This exploitation can lead to unauthorized execution of PHP code contained within the included files. As a result, attackers can circumvent access controls, potentially gain access to sensitive data, or execute malicious scripts under certain conditions when images and safe file types are uploaded and included.
Affected Version(s)
The Plus Addons for Elementor Page Builder * <= 5.5.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved