CVE-2025-0968

The ElementsKit Elementor addons plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.4.0 due to a missing capability checks on the get_megamenu_content() function. This makes it possible for unauthenticated attackers to view any item created in Elementor, such as posts, pages and templates including drafts, trashed and private items.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpmet:elementskit_elementor_addons:*:*:*:*:*:wordpress:*:*

History

25 Feb 2025, 20:21

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/elementskit-lite/trunk/modules/megamenu/api.php#L47 - () https://plugins.trac.wordpress.org/browser/elementskit-lite/trunk/modules/megamenu/api.php#L47 - Product
References () https://plugins.trac.wordpress.org/changeset/3237243/ - () https://plugins.trac.wordpress.org/changeset/3237243/ - Patch
References () https://wordpress.org/plugins/elementskit-lite/#developers - () https://wordpress.org/plugins/elementskit-lite/#developers - Product, Release Notes
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/432ac3b1-8f1d-442f-8e8d-62a1f26ba259?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/432ac3b1-8f1d-442f-8e8d-62a1f26ba259?source=cve - Third Party Advisory
First Time Wpmet elementskit Elementor Addons
Wpmet
CWE CWE-862
CPE cpe:2.3:a:wpmet:elementskit_elementor_addons:*:*:*:*:*:wordpress:*:*
Summary
  • (es) El complemento ElementsKit Elementor para WordPress es vulnerable a la exposición de información confidencial en todas las versiones hasta la 3.4.0 incluida debido a la falta de comprobaciones de capacidad en la función get_megamenu_content(). Esto permite que atacantes no autenticados vean cualquier elemento creado en Elementor, como publicaciones, páginas y plantillas, incluidos borradores, elementos eliminados y privados.

19 Feb 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-19 12:15

Updated : 2025-02-25 20:21


NVD link : CVE-2025-0968

Mitre link : CVE-2025-0968

CVE.ORG link : CVE-2025-0968


JSON object : View

Products Affected

wpmet

  • elementskit_elementor_addons
CWE
CWE-284

Improper Access Control

CWE-862

Missing Authorization