CVE-2024-56282
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 7, 2025
CWE ID 98
Summary
CVE-2024-56282 is a filename manipulation vulnerability affecting the Elicus WPMozo Addons Lite for Elementor plugin. It enables an attacker to include local PHP files through improper control of the filename in the plugin's include/require statements. This issue poses a significant risk, as it can lead to arbitrary code execution on the affected system. The vulnerability affects WPMozo Addons Lite for Elementor from all versions up to and including 1.1.0. Users are strongly advised to update the plugin to the latest, secure version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.