CVE-2024-10693

Published Nov 9, 2024

Last updated 5 days ago

Overview

Description
The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.3 via the Unfold widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from private or draft posts created by Elementor that they should not have access to.
Source
security@wordfence.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
4.3
Impact score
1.4
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

security@wordfence.com
CWE-639

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2024-10693 (Published: 2024-11-09) - A high-severity vulnerability affects SKT Themes. Ensure you're using the latest version of SKT Addons for Elementor to mitigate risks. Check for updates and apply patches immediately! More info: https://t.co/FT2Vbdbp4z

    @transilienceai

    13 Nov 2024

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 CVE-2024-10693 (Published: 2024-11-09) - High severity vulnerability in SKT Themes. Affects SKT Addons for Elementor. Users should update to the latest version immediately to mitigate risks. Stay secure! 🔒 More info: https://t.co/FT2Vbdbp4z

    @transilienceai

    13 Nov 2024

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CVE-2024-10693 (Published: 2024-11-09) - A high-severity vulnerability affects SKT Themes. Versions exploited include SKT Addons for Elementor. 🛠️ Remediation is crucial! Check the latest updates and patches here: https://t.co/x0fjPgV5AT #WordPress #Security

    @transilienceai

    13 Nov 2024

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2024-10693 (Published: 2024-11-09) - A high-severity vulnerability in SKT Themes affects versions of SKT Addons for Elementor. Users are urged to update to the latest version to mitigate risks. Stay secure! 🔒 More info: https://t.co/x0fjPgVDqr

    @transilienceai

    9 Nov 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-10693 The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.3 via the Unfold widget due to insuffi… https://t.co/iWBSmQeggx

    @CVEnew

    9 Nov 2024

    386 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes