QID 150776
Date Published: 2024-01-17
QID 150776: WordPress ElementsKit Plugin: Unauthenticated Sensitive Information Exposure Vulnerability (CVE-2023-6582)
Elements Kit is an all in one advanced addon built to enhance the page builder with widgets and features.
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure via the ekit_widgetarea_content function. This makes it possible for unauthenticated attackers to obtain contents of posts in draft, private or pending review status that should not be visible to the general public. This applies to posts created with Elementor only.
Affected Versions:
WordPress Elements Kit Plugin before 3.0.4
QID Detection Logic:
This QID sends a HTTP GET request and checks for vulnerable version of WordPress plugin running on the target application.
Successful exploitation of this vulnerability could allow an unauthorized attacker to gain Sensitive Information.
CVEs related to QID 150776
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ElementsKit Elementor addons |
|