The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the 'ut_elementor' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
References
Configurations
Configuration 1 (hide)
|
History
06 Mar 2025, 16:36
Type | Values Removed | Values Added |
---|---|---|
First Time |
Uncodethemes ultra Addons Lite For Elementor
Uncodethemes |
|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:uncodethemes:ultra_addons_lite_for_elementor:*:*:*:*:*:wordpress:*:* | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/476883a8-c258-477b-99d3-f35423d7a312?source=cve - Third Party Advisory | |
References | () https://plugins.trac.wordpress.org/browser/ut-elementor-addons-lite/trunk/includes/queries.php#L506 - Product |
28 Feb 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-28 09:15
Updated : 2025-03-06 16:36
NVD link : CVE-2024-13832
Mitre link : CVE-2024-13832
JSON object : View
Products Affected
uncodethemes
- ultra_addons_lite_for_elementor
CWE