The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and future scheduled posts.
History

Wed, 02 Oct 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Themesflat
Themesflat themesflat Addons For Elementor
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:themesflat:themesflat_addons_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Themesflat
Themesflat themesflat Addons For Elementor

Wed, 25 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 25 Sep 2024 03:45:00 +0000

Type Values Removed Values Added
Description The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract limited post information from draft and future scheduled posts.
Title Themesflat Addons For Elementor <= 2.2.1 - Authenticated (Contributor+) Information Exposure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-09-25T03:27:40.542Z

Updated: 2024-09-25T13:27:00.186Z

Reserved: 2024-09-06T14:17:27.705Z

Link: CVE-2024-8516

cve-icon Vulnrichment

Updated: 2024-09-25T13:26:53.545Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-25T04:15:05.000

Modified: 2024-10-02T19:22:44.933

Link: CVE-2024-8516

cve-icon Redhat

No data.