Sensitive Information Exposure Vulnerability in Elementor Addons Plugin
CVE-2024-9541

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2024

What is CVE-2024-9541?

The News Kit Elementor Addons plugin for WordPress is affected by a vulnerability that permits authenticated attackers with Contributor-level access and above to exploit the render function found in includes/widgets/canvas-menu/canvas-menu.php. This flaw enables the extraction of sensitive private, pending, and draft Elementor template data, potentially compromising user privacy and data integrity across affected WordPress installations.

Affected Version(s)

News Kit Addons For Elementor 0 <= 1.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.