CVE-2024-1358

HIGH

Elementor Addon Elements < 1.12.12 - Authenticated Path Traversal via Render Function

Title source: llm
STIX 2.1

Description

The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to include the contents of arbitrary PHP files on the server, which may expose sensitive information.

Scores

CVSS v3 8.8
EPSS 0.0123
EPSS Percentile 65.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
webtechstreet/elementor_addon_elements < 1.13
wpvibes/Addon Elements for Elementor (formerly Elementor Addon Elements) < 1.12.12
Published Mar 13, 2024
Tracked Since Feb 18, 2026