Vulnerabilities (CVE)

Filtered by vendor Unlimited-elements Subscribe
Filtered by product Addon Library
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-1710 1 Unlimited-elements 1 Addon Library 2025-02-27 N/A 8.8 HIGH
The Addon Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the onAjaxAction function action in all versions up to, and including, 1.3.76. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform several unauthorized actions including uploading arbitrary files.