CVE · High

CVE-2024-3500 — ElementsKit [elementskit] < 3.6.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-3500 ElementsKit [elementskit] < 3.6.1 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') High 8.8 < 3.6.1 3.6.1 2024-04-25

CVE-2024-3500

The ElementsKit Pro plugin for WordPress through version 3.6.0 contains a local file inclusion flaw affecting the Price Menu, Hotspot, and Advanced Toggle widgets. Authenticated users with contributor-level permissions or higher can exploit this vulnerability to include and execute arbitrary files from the server, potentially running malicious PHP code. This could allow attackers to circumvent security restrictions, access confidential information, or execute code by uploading and including benign-appearing files like images. The issue was resolved in version 3.6.1.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.