CVE-2024-7063: ElementsKit Pro <= 3.6.6 - Authenticated (Contributor+) Sensitive Information Exposure
The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.6 via the 'renderraw' function. This can allow authenticated attackers, with Contributor-level permissions and above, to extract sensitive data including private, future, and draft posts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7063?
CVE-2024-7063 is considered a medium severity vulnerability due to the potential for sensitive information exposure.
How do I fix CVE-2024-7063?
To fix CVE-2024-7063, update the ElementsKit Pro plugin to version 3.6.7 or later.
Who is affected by CVE-2024-7063?
CVE-2024-7063 affects all versions of the ElementsKit Pro plugin for WordPress up to and including 3.6.6.
What type of data is exposed in CVE-2024-7063?
CVE-2024-7063 allows authenticated users with Contributor-level permissions and above to extract sensitive data.
What is the specific function involved in CVE-2024-7063?
The vulnerability in CVE-2024-7063 is related to the 'render_raw' function within the ElementsKit Pro plugin.