CVE-2024-6455

CVSS V2 None CVSS V3 None
Description
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, pending and private items.
Overview
  • CVE ID
  • CVE-2024-6455
  • Assigner
  • Wordfence
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-18T20:32:37.651Z
  • Last Modified Date
  • 2024-07-18T20:32:37.651Z
History
Created Old Value New Value Data Type Notes
2024-07-19 13:05:53 Added to TrackCVE