4.3
CVE-2024-10050
- EPSS 0.35%
- Veröffentlicht 24.10.2024 09:15:02
- Zuletzt bearbeitet 29.01.2025 17:00:56
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Elementor Header & Footer Builder <= 1.6.43 - Authenticated (Contributor+) Information Disclosure via Shortcode
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.
Mögliche Gegenmaßnahme
Ultimate Addons for Elementor: Update to version 1.6.44, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Ultimate Addons for Elementor
Version
*-1.6.43
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Brainstormforce ≫ Elementor Header & Footer Builder SwPlatformwordpress Version < 1.6.44
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.35% | 0.567 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.