Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47840 | The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'check_temp_validity' and 'update_template_title' functions in all versions up to, and including, 4.10.38. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary content and update post and page titles. |
Wed, 08 Jan 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Leap13
Leap13 premium Addons For Elementor |
|
| CPEs | cpe:2.3:a:leap13:premium_addons_for_elementor:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Leap13
Leap13 premium Addons For Elementor |
Fri, 09 Aug 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Aug 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'check_temp_validity' and 'update_template_title' functions in all versions up to, and including, 4.10.38. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary content and update post and page titles. | |
| Title | Premium Addons for Elementor <= 4.10.38 - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion and Arbitrary Title Update | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:16:26.825Z
Reserved: 2024-07-16T23:15:15.278Z
Link: CVE-2024-6824
Updated: 2024-08-09T17:49:23.294Z
Status : Analyzed
Published: 2024-08-08T06:15:41.067
Modified: 2025-01-08T21:19:51.450
Link: CVE-2024-6824
No data.
OpenCVE Enrichment
No data.
EUVD