The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 via the Content Reveal widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Dec 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 06 Dec 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.8.1 via the Content Reveal widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to. | |
Title | PowerPack Elementor Addons (Free Widgets, Extensions and Templates) <= 2.8.1 - Authenticated (Contributor+) Post Disclosure | |
Weaknesses | CWE-639 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-12-06T08:24:58.199Z
Updated: 2024-12-06T14:18:27.882Z
Reserved: 2024-11-01T16:02:39.998Z
Link: CVE-2024-10692
Vulnrichment
Updated: 2024-12-06T14:11:08.820Z
NVD
Status : Received
Published: 2024-12-06T09:15:05.190
Modified: 2024-12-06T09:15:05.190
Link: CVE-2024-10692
Redhat
No data.