CVE-2024-9530: Qi Addons For Elementor <= 1.8.0 - Sensitive Information Exposure
The Qi Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.0 via private templates. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the contents of templates that are private.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9530?
CVE-2024-9530 has a medium severity rating due to the potential exposure of sensitive information.
How do I fix CVE-2024-9530?
To fix CVE-2024-9530, update the Qi Addons For Elementor plugin to version 1.8.1 or later.
Who is affected by CVE-2024-9530?
Authenticated users with Contributor-level access and above in WordPress are affected by CVE-2024-9530.
What data can be exposed due to CVE-2024-9530?
Due to CVE-2024-9530, sensitive information from private templates can be exposed to authenticated attackers.
Which versions of the Qi Addons For Elementor plugin are vulnerable to CVE-2024-9530?
All versions up to and including 1.8.0 of the Qi Addons For Elementor plugin are vulnerable to CVE-2024-9530.