Vulnerability in Addons For Elementor plugin allows limited post information extraction by authenticated attackers
CVE-2024-8516

4.3MEDIUM

Key Information:

Vendor
Themesflat
Status
Themesflat Addons For Elementor
Vendor
CVE Published:
25 September 2024

Summary

The Themesflat Addons for Elementor plugin for WordPress is susceptible to an information exposure flaw that affects all versions up to 2.2.1. This vulnerability arises due to improper handling in the render() function, permitting authenticated users with Contributor-level permissions or higher to access sensitive details from draft and scheduled posts. Such unauthorized information extraction poses a significant risk to the confidentiality of unpublished content on WordPress sites utilizing this plugin.

Affected Version(s)

Themesflat Addons For Elementor * <= 2.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Craig Smith
.