CVE-2024-12102
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2024-12102 is a newly identified Information Exposure vulnerability affecting the Typer Core plugin for WordPress. This issue, present in all versions up to 1.9.6, allows authenticated attackers, including those with Contributor-level access and above, to extract data from private or draft posts created by Elementor. The vulnerability stems from insufficient restrictions on which posts can be included via the 'elementor-template' shortcode, making it important for WordPress users to update their Typer Core plugin to a newer, patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.