CVE-2024-3500
The ElementsKit Pro plugin for WordPress through version 3.6.0 contains a local file inclusion flaw affecting the Price Menu, Hotspot, and Advanced Toggle widgets. Authenticated users with contributor-level permissions or higher can exploit this vulnerability to include and execute arbitrary files from the server, potentially running malicious PHP code. This could allow attackers to circumvent security restrictions, access confidential information, or execute code by uploading and including benign-appearing files like images. The issue was resolved in version 3.6.1.
Based on public CVE data (MITRE/NVD).