First published: Wed Oct 16 2024(Updated: )
: Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows : Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.121.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
Unlimited Elements For Elementor | <1.5.122 | |
Unlimited Elements for Elementor | <=1.5.121 | |
WordPress Unlimited Elements For Elementor | <=1.5.121 |
Update to 1.5.122 or a higher version.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49271 is considered a high severity vulnerability due to its potential for command injection.
To fix CVE-2024-49271, update Unlimited Elements For Elementor to the latest version beyond 1.5.121.
CVE-2024-49271 could allow attackers to execute arbitrary commands on the server, compromising website security.
Versions of Unlimited Elements For Elementor up to and including 1.5.121 are affected by CVE-2024-49271.
Yes, CVE-2024-49271 is exploitable remotely, allowing attackers to gain control over the affected application.