CVE-2024-3733

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.9.15 via the ajax_load_more() , eael_woo_pagination_product_ajax(), and ajax_eael_product_gallery() functions. This makes it possible for unauthenticated attackers to extract posts that may be in private or draft status.
Configurations

No configuration.

History

25 Apr 2024, 13:18

Type Values Removed Values Added
Summary
  • (es) Los complementos Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders para WordPress son vulnerables a la exposición de información confidencial en todas las versiones hasta la 5.9.15 incluida a través de ajax_load_more(), eael_woo_pagination_product_ajax() y ajax_eael_product_gallery( ) funciones. Esto hace posible que atacantes no autenticados extraigan publicaciones que pueden estar en estado privado o borrador.

25 Apr 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-25 09:15

Updated : 2024-04-25 13:18


NVD link : CVE-2024-3733

Mitre link : CVE-2024-3733

CVE.ORG link : CVE-2024-3733


JSON object : View

Products Affected

No product.

CWE

No CWE.