The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.3 via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status that should not be visible to the general public. This applies to posts created with Elementor only.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-01-11T08:33:11.987Z

Updated: 2024-08-02T08:35:14.890Z

Reserved: 2023-12-07T13:32:34.116Z

Link: CVE-2023-6582

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-11T09:15:49.617

Modified: 2024-01-17T18:45:11.677

Link: CVE-2023-6582

cve-icon Redhat

No data.