nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-4345 CVE-2024-4345
CRITICAL
Startklar Elementor Addons <= 1.7.13 - Unauthenticated Arbitrary File Upload
Record summary
CVE-2024-4345 has a selected CVSS score of 9.8 (critical).
Description
The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process' function in the 'startklarDropZoneUploadProcess' class in versions up to, and including, 1.7.13. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 6, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 7, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Elementor Addons plugin for WordPressBrowse Startklar / Elementor Addons plugin for WordPress | VulnCheck | Version data not supplied | |
Startklar Elementor AddonsBrowse wshberlin / Startklar Elementor AddonsDefault status: unaffected | CVE List | Through 1.7.13 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/startklar-elmentor-forms-extwidgets/trunk/startklarDropZoneUploadProcess.php?rev=3061298 plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3081987/startklar-elmentor-forms-extwidgets wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/4221b33c-5cfa-48db-92bf-bf25ff3c5a5f?source=cve