First published: Thu Oct 17 2024(Updated: )
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected posts.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Royal Elementor Addons | <=1.3.986 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7417 has a medium severity level due to the potential for information exposure.
To fix CVE-2024-7417, update the Royal Elementor Addons and Templates plugin to version 1.3.987 or later.
CVE-2024-7417 affects authenticated users with subscriber-level access and above in the Royal Elementor Addons plugin.
CVE-2024-7417 allows attackers to extract sensitive data stored within the Royal Elementor Addons plugin.
There are no known workarounds for CVE-2024-7417; upgrading the plugin is the recommended action.