nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-47178 CVE-2023-47178
HIGH
WordPress The Plus Addons for Elementor Pro plugin <= 5.2.8 - Unauthenticated Local File Inclusion vulnerability
Record summary
CVE-2023-47178 has a selected CVSS score of 8.6 (high).
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows PHP Local File Inclusion.This issue affects The Plus Addons for Elementor Pro: from n/a through 5.2.8.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 17, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
The Plus Addons for Elementor ProBrowse POSIMYTH Innovation / The Plus Addons for Elementor ProDefault status: unaffected | CVE List | Through 5.2.8 | affected |
the_plus_addons_for_elementor_proBrowse posimyth / the_plus_addons_for_elementor_proDefault status: unknown | CVE List | Through 5.2.8 | affected |
References
2patchstack.comvdb entry
https://patchstack.com/database/vulnerability/theplus_elementor_addon/wordpress-the-plus-addons-for-elementor-pro-plugin-5-2-8-unauthenticated-local-file-inclusion-vulnerability?_s_id=cve