Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-34347 | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_layouts() function in all versions up to, and including, 5.10.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain a detailed listing of layout templates. |
Wed, 29 Jan 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bdthemes
Bdthemes element Pack |
|
| CPEs | cpe:2.3:a:bdthemes:element_pack:*:*:*:*:lite:wordpress:*:* | |
| Vendors & Products |
Bdthemes
Bdthemes element Pack |
Sat, 28 Dec 2024 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 22 Dec 2024 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the get_layouts() function in all versions up to, and including, 5.10.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain a detailed listing of layout templates. | |
| Title | Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.10.12 - Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:25:25.436Z
Reserved: 2024-11-26T21:41:29.064Z
Link: CVE-2024-11852
Updated: 2024-12-23T16:40:46.940Z
Status : Analyzed
Published: 2024-12-22T02:15:16.510
Modified: 2025-01-29T15:37:30.010
Link: CVE-2024-11852
No data.
OpenCVE Enrichment
No data.
EUVD