CVE · Critical

CVE-2024-4404 — ElementsKit [elementskit] < 3.6.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-4404 ElementsKit [elementskit] < 3.6.3 Server-Side Request Forgery (SSRF) Critical 9.6 < 3.6.3 3.6.3 2024-06-13

CVE-2024-4404

The ElementsKit PRO plugin for WordPress before version 3.6.3 contains a server-side request forgery vulnerability in the 'render_raw' function that allows authenticated users with contributor access or higher to send web requests to any location on behalf of the server. An attacker exploiting this flaw could interact with internal services to read or alter sensitive information accessible from the compromised web application.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.