Privilege Escalation in NotFound K Elements by WordPress
CVE-2024-56000

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 February 2025

What is CVE-2024-56000?

The NotFound K Elements WordPress plugin exhibits an Incorrect Privilege Assignment vulnerability that allows an attacker to escalate privileges. An unauthenticated user could potentially gain unauthorized access and elevated privileges within the application, leading to potential account takeover and security breaches.

Affected Version(s)

K Elements < 5.4.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.