CVE-2024-12102

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 30, 2025
Updated: Jan 31, 2025
CWE ID 639

Summary

CVE-2024-12102 is a newly identified Information Exposure vulnerability affecting the Typer Core plugin for WordPress. This issue, present in all versions up to 1.9.6, allows authenticated attackers, including those with Contributor-level access and above, to extract data from private or draft posts created by Elementor. The vulnerability stems from insufficient restrictions on which posts can be included via the 'elementor-template' shortcode, making it important for WordPress users to update their Typer Core plugin to a newer, patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share