The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.
References
Configurations
History
23 Jan 2025, 17:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/addon-elements-for-elementor-page-builder/trunk/modules/modal-popup/widgets/modal-popup.php#L1058 - Product | |
References | () https://plugins.trac.wordpress.org/changeset/3221982/ - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/4feacb75-0533-4f53-8ce9-3e45ee8336e2?source=cve - Third Party Advisory | |
Summary |
|
|
First Time |
Webtechstreet
Webtechstreet elementor Addon Elements |
|
CWE | NVD-CWE-Other | |
CPE | cpe:2.3:a:webtechstreet:elementor_addon_elements:*:*:*:*:*:wordpress:*:* |
15 Jan 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-15 13:15
Updated : 2025-01-23 17:35
NVD link : CVE-2024-13215
Mitre link : CVE-2024-13215
CVE.ORG link : CVE-2024-13215
JSON object : View
Products Affected
webtechstreet
- elementor_addon_elements
CWE