CVE-2024-12140
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 7, 2025
CWE ID 200
Summary
CVE-2024-12140 is a newly disclosed vulnerability affecting the Elementor Addons AI Addons plugin for WordPress. This issue, present in all versions up to 2.2.1, allows authenticated attackers with Contributor-level access and above to extract information from private or draft templates. The vulnerability stems from insufficient restrictions on which templates can be included via the plugin's render function. This information exposure can lead to unintended disclosure of sensitive data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.