The Qi Addons For Elementor plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior' attributes found in the qi_addons_for_elementor_blog_list shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include remote files on the server, resulting in code execution. Please note that this requires an attacker to create a non-existent directory or target an instance where file_exists won't return false with a non-existent directory in the path, in order to successfully exploit.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.03909}

epss

{'score': 0.14175}


Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.02936}

epss

{'score': 0.03909}


Tue, 29 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Qodeinteractive
Qodeinteractive qi Addons For Elementor
Weaknesses CWE-706
CPEs cpe:2.3:a:qodeinteractive:qi_addons_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Qodeinteractive
Qodeinteractive qi Addons For Elementor

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T20:55:10.265Z

Reserved: 2024-05-14T22:12:38.932Z

Link: CVE-2024-4887

cve-icon Vulnrichment

Updated: 2024-08-01T20:55:10.265Z

cve-icon NVD

Status : Modified

Published: 2024-06-07T04:15:31.777

Modified: 2024-11-21T09:43:47.697

Link: CVE-2024-4887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.