CVE-2024-30496: WordPress Element Pack Lite plugin <= 5.5.3 - SQL Injection vulnerability
Published Mar 29, 2024
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BdThemes Element Pack Elementor Addons.This issue affects Element Pack Elementor Addons: from n/a through 5.5.3.
Affected Software
3 affected components
bdthemes Element Pack Wordpress<5.5.4
bdthemes Element Pack Elementor Addons<=5.5.3
WordPress Element Pack Lite<=5.5.3
Remediation
Information
Update to 5.5.4 or a higher version.
Event History
Mar 29, 2024
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-30496?
CVE-2024-30496 has been categorized as a high severity SQL injection vulnerability.
2
How do I fix CVE-2024-30496?
To fix CVE-2024-30496, you should update BdThemes Element Pack Elementor Addons to the latest version beyond 5.5.3.
3
What versions of Element Pack Elementor Addons are affected by CVE-2024-30496?
CVE-2024-30496 affects all versions of BdThemes Element Pack Elementor Addons from n/a through 5.5.3.
4
Is WordPress Element Pack Lite vulnerable to CVE-2024-30496?
Yes, WordPress Element Pack Lite versions up to 5.5.3 are also vulnerable to CVE-2024-30496.
5
What type of vulnerability is CVE-2024-30496?
CVE-2024-30496 is classified as an SQL injection vulnerability that allows improper neutralization of special elements in SQL commands.