CVE Database /
CVE-2024-7145
CVE · High
CVE-2024-7145 — JetElements For Elementor [jet-elements] < 2.6.20.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-7145
|
JetElements For Elementor [jet-elements] < 2.6.20.1 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
8.8
|
< 2.6.20.1
|
2.6.20.1 |
2024-08-15 |
—
|
CVE-2024-7145
Authenticated users with Contributor-level privileges or higher can exploit a Local File Inclusion vulnerability in JetElements plugin versions prior to 2.6.20 by manipulating the 'progress_type' parameter. This weakness enables attackers to load and run arbitrary server files, effectively executing any embedded PHP code within those files. The vulnerability poses risks for sensitive data exposure and unauthorized code execution.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings