PT-2025-1605 · WordPress · Piotnet Addons For Elementor

·

CVE-2024-10775

·

Publicado

2025-01-15

·

Atualizado

2025-01-15

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Piotnet Addons For Elementor plugin for WordPress versions up to, and including, 2.4.32
Description The issue allows authenticated attackers with Contributor-level access and above to extract data from private or draft posts created by Elementor that they should not have access to. This is due to insufficient restrictions on which posts can be included via the 'pafe-template' shortcode.
Recommendations For versions up to, and including, 2.4.32, consider disabling the 'pafe-template' shortcode until a patch is available to prevent exploitation. Restrict access to private or draft posts created by Elementor to minimize the risk of data exposure. Update to a version later than 2.4.32 once available.

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2024-10775

Produtos afetados

Piotnet Addons For Elementor