CVE · Medium

CVE-2024-7063 — ElementsKit [elementskit] < 3.6.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7063 ElementsKit [elementskit] < 3.6.7 Exposure of Sensitive Information to an Unauthorized Actor Medium 4.3 < 3.6.7 3.6.7 2024-08-14

CVE-2024-7063

Authenticated users with contributor privileges or higher can access sensitive information in WordPress installations using ElementsKit Pro plugin versions up to 3.6.6 due to a vulnerability in the 'render_raw' function. This flaw enables unauthorized extraction of confidential post data, encompassing private, upcoming, and draft content.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.