Vulnerability in Addons For Elementor plugin allows limited post information extraction by authenticated attackers
CVE-2024-8516
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 25 September 2024
What is CVE-2024-8516?
The Themesflat Addons for Elementor plugin for WordPress is susceptible to an information exposure flaw that affects all versions up to 2.2.1. This vulnerability arises due to improper handling in the render() function, permitting authenticated users with Contributor-level permissions or higher to access sensitive details from draft and scheduled posts. Such unauthorized information extraction poses a significant risk to the confidentiality of unpublished content on WordPress sites utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Themesflat Addons For Elementor * <= 2.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved