Vulnerability in Addons For Elementor plugin allows limited post information extraction by authenticated attackers
CVE-2024-8516
4.3MEDIUM
Key Information:
- Vendor
- Themesflat
- Status
- Themesflat Addons For Elementor
- Vendor
- CVE Published:
- 25 September 2024
Summary
The Themesflat Addons for Elementor plugin for WordPress is susceptible to an information exposure flaw that affects all versions up to 2.2.1. This vulnerability arises due to improper handling in the render() function, permitting authenticated users with Contributor-level permissions or higher to access sensitive details from draft and scheduled posts. Such unauthorized information extraction poses a significant risk to the confidentiality of unpublished content on WordPress sites utilizing this plugin.
Affected Version(s)
Themesflat Addons For Elementor * <= 2.2.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Craig Smith