CVE · High

CVE-2024-7145 — JetElements For Elementor [jet-elements] < 2.6.20.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7145 JetElements For Elementor [jet-elements] < 2.6.20.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.8 < 2.6.20.1 2.6.20.1 2024-08-15

CVE-2024-7145

Authenticated users with Contributor-level privileges or higher can exploit a Local File Inclusion vulnerability in JetElements plugin versions prior to 2.6.20 by manipulating the 'progress_type' parameter. This weakness enables attackers to load and run arbitrary server files, effectively executing any embedded PHP code within those files. The vulnerability poses risks for sensitive data exposure and unauthorized code execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.