The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redefiningtheweb
Redefiningtheweb pdf Generator Addon For Elementor Page Builder |
|
| CPEs | cpe:2.3:a:redefiningtheweb:pdf_generator_addon_for_elementor_page_builder:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Redefiningtheweb
Redefiningtheweb pdf Generator Addon For Elementor Page Builder |
|
| Metrics |
ssvc
|
Sat, 16 Nov 2024 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. | |
| Title | PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Arbitrary File Download | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-16T03:20:45.226Z
Updated: 2024-11-19T15:14:19.116Z
Reserved: 2024-10-14T13:28:12.183Z
Link: CVE-2024-9935
Updated: 2024-11-18T21:52:50.467Z
Status : Awaiting Analysis
Published: 2024-11-16T04:15:08.103
Modified: 2024-11-18T17:11:17.393
Link: CVE-2024-9935
No data.