CVE Database /
CVE-2023-47679
CVE · Medium
CVE-2023-47679 — Qi Addons For Elementor [qi-addons-for-elementor] < 1.6.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2023-47679
|
Qi Addons For Elementor [qi-addons-for-elementor] < 1.6.4 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Medium
6.4
|
< 1.6.4
|
1.6.4 |
2023-11-09 |
—
|
CVE-2023-47679
The Qi Addons For Elementor plugin versions below 1.6.4 contain a local file inclusion vulnerability that allows attackers to access and display the contents of files stored on the affected website. An attacker could potentially retrieve sensitive files containing credentials, such as database login information, which could lead to unauthorized database access. The vendor has not released a patch for this issue and has not responded to vulnerability reports. This flaw remains unresolved in the plugin.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings