CVE-2024-56000
CRITICALSeventhQueen K Elements <5.4.0 - Privilege Escalation
Title source: llmDescription
Incorrect Privilege Assignment vulnerability in SeventhQueen K Elements k-elements allows Privilege Escalation.This issue affects K Elements: from n/a through < 5.4.0.
References (4)
Core 4
Core References
Vdb Entry vdb-entry
https://patchstack.com/database/Wordpress/Plugin/k-elements/vulnerability/wordpress-k-elements-plugin-5-2-0-unauthenticated-account-takeover-vulnerability?_s_id=cve
Various Sources
https://themeforest.net/item/kleo-pro-community-focused-multipurpose-buddypress-theme/6776630?_s_id=cve
Scores
CVSS v3
9.8
EPSS
0.0050
EPSS Percentile
38.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-266
Status
published
Products (1)
SeventhQueen/K Elements
< 5.4.0
Published
Feb 18, 2025
Tracked Since
Feb 18, 2026