CVE-2024-12061
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-12061 is a newly disclosed vulnerability affecting the Events Addon for Elementor plugin used in WordPress websites. This issue allows authenticated attackers with Contributor-level access and above to gain unauthorized access to information from private or draft posts created with Elementor. The shortcoming lies in the naevents_elementor_template shortcode, which fails to impose sufficient restrictions on the posts that can be included. This vulnerability can result in sensitive data exposure, potentially leading to further security risks. It is recommended that users upgrade to the latest version of the plugin, 2.2.4 or above, to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.