Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34359 | The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.0 via the Popup block due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts that they should not have access to. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 13 Jan 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 11 Jan 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.0 via the Popup block due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts that they should not have access to. | |
| Title | RRAddons for Elementor <= 1.1.0 - Authenticated (Contributor+) Post Disclosure | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-13T17:16:58.995Z
Reserved: 2024-11-27T17:27:12.357Z
Link: CVE-2024-11915
Updated: 2025-01-13T17:16:49.619Z
Status : Received
Published: 2025-01-11T08:15:24.680
Modified: 2025-01-11T08:15:24.680
Link: CVE-2024-11915
No data.
OpenCVE Enrichment
No data.
EUVD