First published: Mon Jan 10 2022(Updated: )
The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_dl_post_info_ajax AJAX action, which could allow unauthenticated users to retrieve sensitive information, such as private and draft posts
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Posimyth The Plus Addons For Elementor | <5.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24948 is the identifier for a vulnerability found in The Plus Addons for Elementor - Pro WordPress plugin before version 5.0.7.
CVE-2021-24948 has a severity rating of 7.5 (High).
Unauthenticated users can exploit CVE-2021-24948 by retrieving sensitive information, such as private and draft posts, through the tp_get_dl_post_info_ajax AJAX action.
The Plus Addons for Elementor - Pro WordPress plugin versions up to and excluding 5.0.7 are affected by CVE-2021-24948.
Yes, you can find more information about CVE-2021-24948 at the following references: https://roadmap.theplusaddons.com/updates, https://wpscan.com/vulnerability/2b67005a-476e-4772-b15c-3191911a50b0