Sensitive Information Exposure in Plugin
CVE-2024-8910
4.3MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 25 September 2024
Summary
The HT Mega – Absolute Addons For Elementor plugin for WordPress has a vulnerability that allows for the exposure of sensitive information. All versions up to and including 2.6.5 are susceptible to this issue, specifically through the render function located in includes/widgets/htmega_accordion.php. This vulnerability permits authenticated users with Contributor-level access and higher to improperly access and extract confidential data related to private, pending, and draft templates, potentially compromising the security and integrity of affected WordPress sites.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published