The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the render function in includes/widgets/canvas-menu/canvas-menu.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft Elementor template data.
History

Fri, 25 Oct 2024 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Blazethemes
Blazethemes news Kit Elementor Addons
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:blazethemes:news_kit_elementor_addons:*:*:*:*:*:wordpress:*:*
Vendors & Products Blazethemes
Blazethemes news Kit Elementor Addons

Tue, 22 Oct 2024 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Oct 2024 07:45:00 +0000

Type Values Removed Values Added
Description The News Kit Elementor Addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.2.1 via the render function in includes/widgets/canvas-menu/canvas-menu.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft Elementor template data.
Title News Kit Elementor Addons <= 1.2.1 - Authenticated (Contributor+) Sensitive Information Exposure via Canvas Menu Elementor Template
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-10-22T07:36:35.355Z

Updated: 2024-10-22T13:14:20.285Z

Reserved: 2024-10-04T18:49:02.680Z

Link: CVE-2024-9541

cve-icon Vulnrichment

Updated: 2024-10-22T13:14:16.698Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-22T08:15:02.920

Modified: 2024-10-25T21:16:12.447

Link: CVE-2024-9541

cve-icon Redhat

No data.