First published: Tue Apr 09 2024(Updated: )
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPDeveloper Essential Addons for Elementor | <5.9.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2974 has a medium severity rating due to its potential to expose sensitive information.
To fix CVE-2024-2974, update the Essential Addons for Elementor plugin to version 5.9.14 or later.
Users of the Essential Addons for Elementor plugin for WordPress versions up to and including 5.9.13 are affected by CVE-2024-2974.
CVE-2024-2974 exploits the load_more function within the Essential Addons for Elementor plugin to allow sensitive information exposure.
CVE-2024-2974 can be exploited by unauthenticated attackers, making it critical for all users to update their plugin.