CVE Database /
CVE-2024-3499
CVE · High
CVE-2024-3499 — ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.1.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-3499
|
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor [elementskit-lite] < 3.1.1 |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') |
High
8.8
|
< 3.1.1
|
3.1.1 |
2024-04-22 |
—
|
CVE-2024-3499
The ElementsKit Elementor Addons plugin through version 3.1.0 contains a local file inclusion flaw in the Onepage Scroll module's generate_navigation_markup function that allows authenticated users with contributor privileges or higher to include and execute arbitrary files from the server. By exploiting this vulnerability, attackers can run arbitrary PHP code, potentially compromising access controls, exposing confidential information, or executing malicious code when combined with uploads of executable files disguised as safe file types. The issue was remedied in version 3.1.1.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings