CVE-2024-10316: Stratum – Elementor Widgets <= 1.4.4 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates
The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.4 in includes/templates/content-switcher.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10316?
CVE-2024-10316 is classified as a moderate severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2024-10316?
To fix CVE-2024-10316, update the Stratum – Elementor Widgets plugin to version 1.4.5 or later.
Who is affected by CVE-2024-10316?
CVE-2024-10316 affects authenticated users with Contributor-level access or higher in all versions of the Stratum – Elementor Widgets plugin up to 1.4.4.
What types of information can be exposed by CVE-2024-10316?
CVE-2024-10316 may lead to unauthorized access to sensitive user information stored within the plugin.
Is CVE-2024-10316 still exploitable after updating?
No, after updating the Stratum – Elementor Widgets plugin to version 1.4.5 or later, the vulnerability CVE-2024-10316 is no longer exploitable.