CVE-2024-8902: Elementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure via table_saved_sections
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the rendercolumn function in modules/data-table/widgets/data-table.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8902?
CVE-2024-8902 is classified as a vulnerability that can lead to sensitive information exposure.
How do I fix CVE-2024-8902?
To fix CVE-2024-8902, update the Elementor Addon Elements plugin to version 1.13.9 or later.
Who is affected by CVE-2024-8902?
CVE-2024-8902 affects all versions of the Elementor Addon Elements plugin for WordPress up to and including 1.13.8.
What causes CVE-2024-8902?
CVE-2024-8902 is caused by the render_column function in the modules/data-table/widgets/data-table.php file within the plugin.
Can attackers exploit CVE-2024-8902 without authentication?
No, attackers need to be authenticated to exploit CVE-2024-8902.