Sensitive Information Exposure in Plugin
CVE-2024-8910
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 25 September 2024
What is CVE-2024-8910?
The HT Mega β Absolute Addons For Elementor plugin for WordPress has a vulnerability that allows for the exposure of sensitive information. All versions up to and including 2.6.5 are susceptible to this issue, specifically through the render function located in includes/widgets/htmega_accordion.php. This vulnerability permits authenticated users with Contributor-level access and higher to improperly access and extract confidential data related to private, pending, and draft templates, potentially compromising the security and integrity of affected WordPress sites.
Affected Version(s)
HT Mega Addons for Elementor β Elementor Widgets & Template Builder 0 <= 2.6.5