CVE-2024-13335
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 24, 2025
Updated: Feb 5, 2025
CWE ID 862
Summary
CVE-2024-13335 is a vulnerability affecting the Spexo Addons for Elementor plugin for WordPress. The issue lies in the tmpcoder_theme_install_func() function, which lacks adequate capability checks. This oversight allows authenticated attackers, with Subscriber-level access or higher, to install themes unauthorizedly. Successful exploitation could lead to unintended plugin installations and potential security risks. Users are advised to update the Spexo Addons for Elementor plugin to a version beyond 1.0.14 to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share