CVE-2024-10050: Elementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via Shortcode
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfetemplate shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10050?
CVE-2024-10050 has a high severity rating due to its potential for information disclosure.
How do I fix CVE-2024-10050?
To fix CVE-2024-10050, update the Elementor Header & Footer Builder plugin to version 1.6.44 or higher.
Who is affected by CVE-2024-10050?
Authenticated users with Contributor-level access and above can exploit CVE-2024-10050.
What versions of Elementor Header & Footer Builder are vulnerable to CVE-2024-10050?
All versions of Elementor Header & Footer Builder up to and including 1.6.43 are vulnerable to CVE-2024-10050.
What type of vulnerability is CVE-2024-10050?
CVE-2024-10050 is an information disclosure vulnerability.