Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.
Fixes

Solution

Update the WordPress Premium Addons for Elementor plugin to the latest available version (at least 4.10.57).


Workaround

No workaround given by the vendor.

History

Thu, 06 Mar 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Leap13
Leap13 premium Addons For Elementor
CPEs cpe:2.3:a:leap13:premium_addons_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Leap13
Leap13 premium Addons For Elementor

Tue, 31 Dec 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 31 Dec 2024 10:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Leap13 Premium Addons for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Premium Addons for Elementor: from n/a through 4.10.56.
Title WordPress Premium Addons for Elementor plugin <= 4.10.56 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2024-12-31T15:40:33.152Z

Reserved: 2024-12-18T19:04:02.339Z

Link: CVE-2024-56225

cve-icon Vulnrichment

Updated: 2024-12-31T15:40:28.604Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-31T11:15:08.380

Modified: 2025-03-06T19:02:47.083

Link: CVE-2024-56225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.