The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to include the contents of arbitrary PHP files on the server, which may expose sensitive information.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-03-13T15:26:37.292Z
Updated: 2024-08-08T20:19:03.701Z
Reserved: 2024-02-08T18:18:46.714Z
Link: CVE-2024-1358
Vulnrichment
Updated: 2024-08-01T18:33:25.444Z
NVD
Status : Awaiting Analysis
Published: 2024-03-13T16:15:19.870
Modified: 2024-11-21T08:50:24.403
Link: CVE-2024-1358
Redhat
No data.