CVE Database /
CVE-2024-12061
CVE · Medium
CVE-2024-12061 — Events Addon for Elementor [events-addon-for-elementor] < 2.2.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-12061
|
Events Addon for Elementor [events-addon-for-elementor] < 2.2.4 |
Authorization Bypass Through User-Controlled Key |
Medium
4.3
|
< 2.2.4
|
2.2.4 |
2024-12-17 |
—
|
CVE-2024-12061
The Events Addon for Elementor plugin contains an information disclosure vulnerability affecting versions 2.2.3 and earlier through the naevents_elementor_template shortcode, which lacks proper access controls on post retrieval. Authenticated users with Contributor permissions or higher can exploit this flaw to view sensitive content from private or draft posts created with Elementor that would normally be restricted from their access. The vulnerability was resolved in version 2.2.4.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings