CVE-2024-5614
The Piotnet Addons For Elementor plugin contains a flaw in the 'pafe_posts_list' function that allows unauthenticated users to access restricted content through versions 2.4.29 and earlier. By exploiting this weakness, attackers can retrieve sensitive information such as post titles and summaries from unpublished content, including drafts and scheduled posts that should not be publicly visible. The vulnerability exposes private editorial data that could be used to gain competitive advantage or identify unreleased information.
Based on public CVE data (MITRE/NVD).