Sensitive Information Exposure in Plugin
CVE-2024-8910
4.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 25 September 2024
What is CVE-2024-8910?
The HT Mega – Absolute Addons For Elementor plugin for WordPress has a vulnerability that allows for the exposure of sensitive information. All versions up to and including 2.6.5 are susceptible to this issue, specifically through the render function located in includes/widgets/htmega_accordion.php. This vulnerability permits authenticated users with Contributor-level access and higher to improperly access and extract confidential data related to private, pending, and draft templates, potentially compromising the security and integrity of affected WordPress sites.