CVE · Medium

CVE-2023-47679 — Qi Addons For Elementor [qi-addons-for-elementor] < 1.6.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-47679 Qi Addons For Elementor [qi-addons-for-elementor] < 1.6.4 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Medium 6.4 < 1.6.4 1.6.4 2023-11-09

CVE-2023-47679

The Qi Addons For Elementor plugin versions below 1.6.4 contain a local file inclusion vulnerability that allows attackers to access and display the contents of files stored on the affected website. An attacker could potentially retrieve sensitive files containing credentials, such as database login information, which could lead to unauthorized database access. The vendor has not released a patch for this issue and has not responded to vulnerability reports. This flaw remains unresolved in the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.