CVE · High

CVE-2024-2966 — Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2966 Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.6.0 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 5.6.0 5.6.0 2024-04-10

CVE-2024-2966

The Element Pack Addons for Elementor plugin through version 5.5.6 contains a sensitive information exposure flaw in the element_pack_ajax_search function that allows unauthenticated users to retrieve confidential data, including details from password-protected posts. This vulnerability affects the Header Footer, Template Library, Dynamic Grid & Carousel, and Remote Arrows components of the plugin. The issue was resolved in version 5.6.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.