Showing 1 vulnerability on this page for ElementsKit Elementor addons

Signals CISA KEV Ransomware Nuclei
wpmet vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

ElementsKit Elementor addons <= 3.2.0 - Unauthenticated Information Exposure via ekit_widgetarea_content Function

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2.0 due to a missing capability checks on ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, pending and private items.

CWE-200CWE-862Jul 18, 2024
CVSS5.3v3.1EPSS0.396%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX