CVE · Medium

CVE-2024-10770 — Envo Extra [envo-extra] < 1.9.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10770 Envo Extra [envo-extra] < 1.9.4 Authorization Bypass Through User-Controlled Key Medium 4.3 < 1.9.4 1.9.4 2024-11-08

CVE-2024-10770

The Envo Extra plugin for WordPress contains an information disclosure flaw affecting version 1.9.3 and earlier through the 'elementor-template' shortcode, which lacks adequate controls over post access permissions. Authenticated users with Contributor-level privileges or higher can exploit this weakness to retrieve content from private and draft posts created using Elementor that would normally be restricted from their view. The vulnerability was resolved in version 1.9.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.