CVE · Medium

CVE-2024-5614 — Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.30

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-5614 Piotnet Addons For Elementor [piotnet-addons-for-elementor] < 2.4.30 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 2.4.30 2.4.30 2024-07-26

CVE-2024-5614

The Piotnet Addons For Elementor plugin contains a flaw in the 'pafe_posts_list' function that allows unauthenticated users to access restricted content through versions 2.4.29 and earlier. By exploiting this weakness, attackers can retrieve sensitive information such as post titles and summaries from unpublished content, including drafts and scheduled posts that should not be publicly visible. The vulnerability exposes private editorial data that could be used to gain competitive advantage or identify unreleased information.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.