nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-4346 CVE-2024-4346
CRITICAL
Startklar Elementor Addons <= 1.7.13 - Unauthenticated Arbitrary File Deletion
Record summary
CVE-2024-4346 has a selected CVSS score of 9.1 (critical).
Description
The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.13. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delete arbitrary files, including the wp-config.php file, which can make site takeover and remote code execution possible.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 4, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 7, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
startklar_elmentor_addonsBrowse web-shop-host / startklar_elmentor_addons | VulnCheck | Version data not supplied | |
Startklar Elementor AddonsBrowse wshberlin / Startklar Elementor AddonsDefault status: unaffected | CVE List | Through 1.7.13 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/startklar-elmentor-forms-extwidgets/trunk/startklarDropZoneUploadProcess.php?rev=3061298 plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3081987/startklar-elmentor-forms-extwidgets wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/a125bbf1-8ff6-4f3d-a4fb-caaaefe1df2a?source=cve