CVE-2024-33568: WordPress Element Pack Pro plugin < 7.19.3 - Arbitrary File Read and Phar Deserialization vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BdThemes Element Pack Pro bdthemes-element-pack.This issue affects Element Pack Pro: from n/a through < 7.19.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33568?
CVE-2024-33568 is classified as a high severity vulnerability due to its potential for path traversal and object injection risks.
How do I fix CVE-2024-33568?
To fix CVE-2024-33568, update the BdThemes Element Pack Pro plugin to version 7.7.5 or later.
What versions of Element Pack Pro are affected by CVE-2024-33568?
CVE-2024-33568 affects all versions of BdThemes Element Pack Pro from n/a up to and including 7.7.4.
What type of vulnerability is CVE-2024-33568?
CVE-2024-33568 is a combination of path traversal and deserialization of untrusted data vulnerabilities.
Who is affected by CVE-2024-33568?
Users of BdThemes Element Pack Pro plugin for WordPress in the affected version range are at risk from CVE-2024-33568.