CVE Database /
CVE-2024-4359
CVE · Medium
CVE-2024-4359 — Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-4359
|
Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] < 5.7.3 |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') |
Medium
6.5
|
< 5.7.3
|
5.7.3 |
2024-08-08 |
—
|
CVE-2024-4359
The Element Pack Elementor Addons plugin for WordPress contains a file read vulnerability affecting versions 5.7.2 and earlier through its SVG widget functionality. The render_svg function fails to properly validate files, allowing authenticated users with contributor privileges or higher to access and view arbitrary files stored on the server. This vulnerability could expose sensitive information by enabling attackers to read confidential file contents. The issue was resolved in version 5.7.3.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings