CVE · High

CVE-2024-3499 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.1.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3499 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.1.1 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 8.8 < 3.1.1 3.1.1 2024-04-22

CVE-2024-3499

The ElementsKit Elementor Addons plugin through version 3.1.0 contains a local file inclusion flaw in the Onepage Scroll module's generate_navigation_markup function that allows authenticated users with contributor privileges or higher to include and execute arbitrary files from the server. By exploiting this vulnerability, attackers can run arbitrary PHP code, potentially compromising access controls, exposing confidential information, or executing malicious code when combined with uploads of executable files disguised as safe file types. The issue was remedied in version 3.1.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.