First published: Wed Mar 13 2024(Updated: )
The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to include the contents of arbitrary PHP files on the server, which may expose sensitive information.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
webtechstreet Elementor Addon Elements | <1.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1358 is considered a critical severity vulnerability due to its potential for unauthorized file inclusion.
To fix CVE-2024-1358, update the Elementor Addon Elements plugin to version 1.13 or higher.
Authenticated users with contributor permissions or higher are affected by CVE-2024-1358.
CVE-2024-1358 is a Directory Traversal vulnerability that allows inclusion of arbitrary PHP files.
All versions up to and including 1.12.12 of the Elementor Addon Elements plugin are affected by CVE-2024-1358.