First published: Wed Nov 15 2023(Updated: )
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.12.7 via the ajax_eae_post_data function. This can allow unauthenticated attackers to extract sensitive data including post/page ids and titles including those of with pending/draft/future/private status.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
webtechstreet Elementor Addon Elements | <=1.12.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-4723 is a vulnerability found in the Elementor Addon Elements plugin for WordPress.
The severity of CVE-2023-4723 is medium.
CVE-2023-4723 can allow unauthenticated attackers to extract sensitive data from the Elementor Addon Elements plugin.
Versions up to and including 1.12.7 of the Elementor Addon Elements plugin are affected by CVE-2023-4723.
Yes, upgrading to a version higher than 1.12.7 of the Elementor Addon Elements plugin will fix CVE-2023-4723.