CVE-2024-10324: RomethemeKit For Elementor <= 1.5.2 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates
The RomethemeKit For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.2 via the registercontrols function in widgets/offcanvas-rometheme.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10324?
The severity of CVE-2024-10324 is classified as a high risk due to its potential for sensitive information exposure.
How do I fix CVE-2024-10324?
To fix CVE-2024-10324, update the RomethemeKit For Elementor plugin to version 1.5.3 or later.
Who is affected by CVE-2024-10324?
All users of the RomethemeKit For Elementor plugin for WordPress versions up to and including 1.5.2 are affected by CVE-2024-10324.
What type of vulnerability is CVE-2024-10324?
CVE-2024-10324 is classified as a Sensitive Information Exposure vulnerability.
Can CVE-2024-10324 be exploited by unauthenticated users?
CVE-2024-10324 requires authentication, meaning only authenticated attackers can exploit this vulnerability.