CVE-2024-43996: WordPress ElementsKit Pro plugin <= 3.6.0 - Local File Inclusion vulnerability
Published Sep 23, 2024
·Updated
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit Pro allows PHP Local File Inclusion.This issue affects ElementsKit Pro: from n/a through 3.6.0.
Affected Software
1 affected component
Wpmet Elementskit Wordpress<=3.6.0
Remediation
Information
Update to 3.6.8 or a higher version.
Event History
Sep 23, 2024
CVE Published
via MITRE·12:01 AM
Data Sourced
via MITRE·12:01 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-43996?
CVE-2024-43996 is considered a critical severity vulnerability due to its potential for local file inclusion.
2
How do I fix CVE-2024-43996?
The recommended fix for CVE-2024-43996 is to upgrade ElementsKit Pro to version 3.6.1 or later.
3
Who is affected by CVE-2024-43996?
CVE-2024-43996 affects users of ElementsKit Pro versions up to and including 3.6.0.
4
What type of vulnerability is CVE-2024-43996?
CVE-2024-43996 is classified as a Path Traversal vulnerability, leading to improper limitation of a pathname.
5
Can CVE-2024-43996 lead to unauthorized access?
Yes, CVE-2024-43996 can allow attackers to perform local file inclusion, potentially leading to unauthorized access to sensitive files.