CVE-2024-33914: WordPress Exclusive Addons for Elementor plugin <= 2.6.9.1 - Broken Access Control on Post Duplication vulnerability
Published May 3, 2024
·Updated
Missing Authorization vulnerability in Exclusive Addons Exclusive Addons Elementor.This issue affects Exclusive Addons Elementor: from n/a through 2.6.9.1.
Affected Software
3 affected components
Exclusiveaddons Exclusive Addons For Elementor Wordpress<2.6.9.2
Exclusive Addons Exclusive Addons Elementor<=2.6.9.1
WordPress Exclusive Addons for Elementor<=2.6.9.1
Remediation
Information
Update to 2.6.9.2 or a higher version.
Event History
May 3, 2024
CVE Published
via MITRE·08:36 AM
Data Sourced
via MITRE·08:36 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Oct 24, 58293
Event
via NVD·06:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-33914?
CVE-2024-33914 is classified as a missing authorization vulnerability that can lead to unauthorized access.
2
How do I fix CVE-2024-33914?
To fix CVE-2024-33914, update Exclusive Addons Elementor to a version higher than 2.6.9.1.
3
Which versions are affected by CVE-2024-33914?
CVE-2024-33914 affects Exclusive Addons Elementor from n/a up to and including version 2.6.9.1.
4
What impact does CVE-2024-33914 have on my website?
CVE-2024-33914 can potentially allow attackers to gain unauthorized access and manipulate content on websites using the affected plugin.
5
Is there a workaround for CVE-2024-33914?
Currently, the best approach is to update the plugin, as there are no known effective workarounds for CVE-2024-33914.