First published: Tue Jun 04 2024(Updated: )
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Deserialization of Untrusted Data vulnerability in BdThemes Element Pack Pro allows Path Traversal, Object Injection.This issue affects Element Pack Pro: from n/a through 7.7.4.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Element Pack Pro | >=n/a<=7.7.4 | |
WordPress Element Pack Pro | <=7.7.4 | |
WordPress Element Pack Pro | <=7.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33568 is classified as a high severity vulnerability due to its potential for path traversal and object injection risks.
To fix CVE-2024-33568, update the BdThemes Element Pack Pro plugin to version 7.7.5 or later.
CVE-2024-33568 affects all versions of BdThemes Element Pack Pro from n/a up to and including 7.7.4.
CVE-2024-33568 is a combination of path traversal and deserialization of untrusted data vulnerabilities.
Users of BdThemes Element Pack Pro plugin for WordPress in the affected version range are at risk from CVE-2024-33568.