CVE Database /
CVE-2024-4404
CVE · Critical
CVE-2024-4404 — ElementsKit [elementskit] < 3.6.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-4404
|
ElementsKit [elementskit] < 3.6.3 |
Server-Side Request Forgery (SSRF) |
Critical
9.6
|
< 3.6.3
|
3.6.3 |
2024-06-13 |
—
|
CVE-2024-4404
The ElementsKit PRO plugin for WordPress before version 3.6.3 contains a server-side request forgery vulnerability in the 'render_raw' function that allows authenticated users with contributor access or higher to send web requests to any location on behalf of the server. An attacker exploiting this flaw could interact with internal services to read or alter sensitive information accessible from the compromised web application.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings