Arbitrary File Inclusion Vulnerability in Plus Addons for Elementor Page Builder
CVE-2024-5455
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 21 June 2024
What is CVE-2024-5455?
The Plus Addons for Elementor Page Builder plugin for WordPress is susceptible to Local File Inclusion (LFI) vulnerabilities across all versions up to and including 5.5.4. The vulnerability leverages the 'magazine_style' parameter within the Dynamic Smart Showcase widget, permitting authenticated attackers with Contributor-level access or higher to include and execute arbitrary files on the server. This exploitation can lead to unauthorized execution of PHP code contained within the included files. As a result, attackers can circumvent access controls, potentially gain access to sensitive data, or execute malicious scripts under certain conditions when images and safe file types are uploaded and included.
Affected Version(s)
The Plus Addons for Elementor Page Builder * <= 5.5.6