CVE-2024-10321CVSS 4.3Web
CVE-2024-10321: all-in-one addons for elementor vulnerability
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 in elements/advanced-tab/template/view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
- CVSS
- 4.3 MEDIUM
- EPSS
- 20.97%
- Known exploited
- not in KEV
- Product
- all-in-one addons for elementor
What is known
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.5 in elements/advanced-tab/template/view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.