First published: Sat Oct 19 2024(Updated: )
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.9 via the Page Loader widget. This makes it possible for authenticated attackers, with contributor-level access and above, to view private/draft/password protected posts, pages, and Elementor templates that they should not have access to.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
ElementInvader Addons for Elementor | <1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9889 is considered a moderate severity vulnerability due to the sensitive information exposure it causes.
To fix CVE-2024-9889, update the ElementInvader Addons for Elementor plugin to version 1.3.0 or later.
CVE-2024-9889 affects all versions of the ElementInvader Addons for Elementor plugin for WordPress up to and including 1.2.9.
CVE-2024-9889 can lead to the exposure of sensitive information accessible to authenticated users with contributor-level access or higher.
While there is no publicly disclosed exploit for CVE-2024-9889, the vulnerability itself poses a risk to user data if not mitigated.