CVE-2024-37091: WordPress Consulting Elementor Widgets plugin <= 1.3.0 - Remote Code Execution (RCE) vulnerability
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0; Masterstudy Elementor Widgets: from n/a through 1.2.2.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37091?
CVE-2024-37091 has a high severity level due to the potential for OS Command Injection.
How do I fix CVE-2024-37091?
To mitigate CVE-2024-37091, update the Consulting Elementor Widgets plugin to version 1.3.2 or later.
Which versions of the software are affected by CVE-2024-37091?
CVE-2024-37091 affects versions of the Consulting Elementor Widgets plugin prior to 1.3.2.
What types of attacks can be performed using CVE-2024-37091?
CVE-2024-37091 allows attackers to execute arbitrary commands on the server through command injection.
Who is impacted by CVE-2024-37091?
Users of the Consulting Elementor Widgets plugin for WordPress versions up to 1.3.1 are impacted by CVE-2024-37091.