CVE · Medium

CVE-2024-6757 — Elementor Website Builder – more than just a page builder [elementor] < 3.24.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-6757 Elementor Website Builder – more than just a page builder [elementor] < 3.24.6 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 3.24.6 3.24.6 2024-10-14

CVE-2024-6757

Authenticated users with contributor-level access or higher in WordPress plugins up to version 3.23.5 can exploit a vulnerability in the Elementor Website Builder plugin's image handling functionality, specifically affecting the get_image_alt function. This flaw enables attackers to retrieve sensitive information from private or password-protected posts by accessing either their titles or excerpts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.