CVE-2024-35725: WordPress LA-Studio Element Kit for Elementor plugin <= 1.3.6 - Broken Access Control vulnerability
Published Jun 10, 2024
·Updated
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.6.
Affected Software
1 affected component
La-studioweb Element Kit For Elementor Wordpress<1.3.7.4
Remediation
Information
Update to 1.3.7.4 or a higher version.
Event History
Jun 10, 2024
CVE Published
via MITRE·07:48 AM
Data Sourced
via MITRE·07:48 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35725?
CVE-2024-35725 is categorized as a Missing Authorization vulnerability.
2
How do I fix CVE-2024-35725?
To fix CVE-2024-35725, update LA-Studio Element Kit for Elementor to version 1.3.7.4 or later.
3
Which versions of LA-Studio Element Kit for Elementor are affected by CVE-2024-35725?
CVE-2024-35725 affects LA-Studio Element Kit for Elementor from n/a up to version 1.3.6.
4
What type of vulnerability is CVE-2024-35725?
CVE-2024-35725 is a Missing Authorization vulnerability that could allow unauthorized access.
5
Who is impacted by CVE-2024-35725?
Users of LA-Studio Element Kit for Elementor versions 1.3.6 and below are impacted by CVE-2024-35725.