CVE-2024-10770
The Envo Extra plugin for WordPress contains an information disclosure flaw affecting version 1.9.3 and earlier through the 'elementor-template' shortcode, which lacks adequate controls over post access permissions. Authenticated users with Contributor-level privileges or higher can exploit this weakness to retrieve content from private and draft posts created using Elementor that would normally be restricted from their view. The vulnerability was resolved in version 1.9.4.
Based on public CVE data (MITRE/NVD).