CVE-2024-13215: Elementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure via Modal Popup
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.10 via the 'render' function in modules/modal-popup/widgets/modal-popup.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, scheduled, and draft template data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13215?
CVE-2024-13215 has a high severity level due to its potential for sensitive information exposure.
How do I fix CVE-2024-13215?
To fix CVE-2024-13215, update the Elementor Addon Elements plugin to version 1.14 or higher.
Who is affected by CVE-2024-13215?
CVE-2024-13215 affects all versions of the Elementor Addon Elements plugin up to and including version 1.13.10.
What type of vulnerability is CVE-2024-13215?
CVE-2024-13215 is classified as a Sensitive Information Exposure vulnerability.
Is authentication required to exploit CVE-2024-13215?
Yes, CVE-2024-13215 can be exploited by authenticated attackers with Contributor-level access.