CVE-2024-6757: Elementor <= 3.23.5 - Authenticated (Contributor+) Basic Information Exposure via get_image_alt Function
The Elementor Website Builder – More than Just a Page Builder plugin for WordPress is vulnerable to Basic Information Exposure in all versions up to, and including, 3.23.5 via the getimagealt function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract either excerpt data or titles of private or password-protected posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6757?
CVE-2024-6757 has a medium severity rating due to the potential for information exposure to authenticated attackers.
Who is affected by CVE-2024-6757?
CVE-2024-6757 affects all versions of the Elementor Website Builder plugin for WordPress up to and including 3.23.5.
How do I fix CVE-2024-6757?
To fix CVE-2024-6757, update the Elementor Website Builder plugin to version 3.24.6 or later.
What kind of data can be exposed by CVE-2024-6757?
CVE-2024-6757 can lead to the exposure of basic information, such as image alt text, to authenticated users with Contributor-level access.
Is there a specific plugin version that closes CVE-2024-6757?
Yes, version 3.24.6 and later of the Elementor Website Builder plugin resolves the vulnerability identified in CVE-2024-6757.