The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-27914 The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 5.9.13 via the load_more function. This can allow unauthenticated attackers to extract sensitive data including private and draft posts.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 08 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpdeveloper
Wpdeveloper essential Addons For Elementor
Weaknesses CWE-922
CPEs cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:*
Vendors & Products Wpdeveloper
Wpdeveloper essential Addons For Elementor

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T19:32:42.482Z

Reserved: 2024-03-27T03:55:57.729Z

Link: CVE-2024-2974

cve-icon Vulnrichment

Updated: 2024-08-01T19:32:42.482Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-09T19:15:38.817

Modified: 2025-01-08T20:06:14.587

Link: CVE-2024-2974

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.