CVE-2024-10356: ElementsReady Addons for Elementor <= 6.4.8 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates
The ElementsReady Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.4.8 in inc/Widgets/accordion/output/content.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10356?
The severity of CVE-2024-10356 is classified as high due to its potential for sensitive information exposure.
How do I fix CVE-2024-10356?
To fix CVE-2024-10356, upgrade to the latest version of the ElementsReady Addons for Elementor plugin beyond version 6.4.8.
Who is affected by CVE-2024-10356?
CVE-2024-10356 affects users of the ElementsReady Addons for Elementor plugin on WordPress with versions up to and including 6.4.8.
What type of vulnerability is CVE-2024-10356?
CVE-2024-10356 is a vulnerability that involves sensitive information exposure.
What access level is needed to exploit CVE-2024-10356?
Authenticated attackers with Contributor-level access can exploit CVE-2024-10356.