ElementsKit Elementor Addons Vulnerability – Unauthenticated Information Exposure via ekit_widgetarea_content Function – CVE-2024-6455 | WordPress Plugin Vulnerability Report

Plugin Name: ElementsKit Elementor addons

Key Information:

  • Software Type: Plugin
  • Software Slug: elementskit-lite
  • Software Status: Active
  • Software Author: xpeedstudio
  • Software Downloads: 21,730,790
  • Active Installs: 1,000,000
  • Last Updated: July 29, 2024
  • Patched Versions: 3.2.1
  • Affected Versions: <= 3.2.0

Vulnerability Details:

  • Name: ElementsKit Elementor addons <= 3.2.0
  • Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • CVE: CVE-2024-6455
  • CVSS Score: 5.4
  • Publicly Published: July 18, 2024
  • Researcher: stealthcopter
  • Description: The ElementsKit Elementor addons plugin for WordPress is vulnerable to information exposure in all versions up to and including 3.2.0 due to missing capability checks on the ekit_widgetarea_content function. This vulnerability allows unauthenticated attackers to view any content created in Elementor, including posts, pages, templates, drafts, pending, and private items.

Summary:

The ElementsKit Elementor addons plugin for WordPress has a vulnerability in versions up to and including 3.2.0 that allows unauthenticated information exposure. This vulnerability has been patched in version 3.2.1.

Detailed Overview:

The vulnerability was identified by researcher stealthcopter and involves missing capability checks in the ekit_widgetarea_content function. This oversight allows unauthenticated attackers to access and view various content types created with Elementor, including private and draft posts, which are typically restricted. The exposure of this content can lead to privacy issues and unauthorized dissemination of sensitive information, although it does not provide attackers with direct control over the site.

Advice for Users:

Immediate Action: Users should update the ElementsKit Elementor addons plugin to version 3.2.1 or later to secure their sites from this vulnerability. Check for Signs of Vulnerability: Review your site's content and access logs to ensure that no unauthorized access has occurred. Monitor for unusual activity, such as unexpected views of drafts or private posts. Alternate Plugins: While the issue has been patched, users might consider exploring other Elementor addons with robust security features to mitigate potential risks. Stay Updated: Regularly updating all plugins and the WordPress core is essential to prevent vulnerabilities and maintain site security.

Conclusion:

The swift action by the ElementsKit developers to address this vulnerability highlights the importance of timely updates. Users are strongly encouraged to ensure they are running version 3.2.1 or later to protect their WordPress sites from unauthorized information exposure.

References:

Detailed Report: 

Ensuring the security of your WordPress website is essential, especially in a landscape where vulnerabilities can compromise both your data and user privacy. Recently, a notable security issue was identified in the ElementsKit Elementor Addons plugin, affecting versions up to 3.2.0. This vulnerability, tracked as CVE-2024-6455, allows unauthenticated attackers to access and view content created with Elementor, including sensitive drafts, pending posts, and private items. Such exposure can lead to significant privacy concerns and unauthorized dissemination of content, highlighting the critical need for regular updates and vigilant security practices.

Details About the Plugin:

The ElementsKit Elementor Addons plugin, developed by xpeedstudio, is widely used to extend the capabilities of Elementor, a popular WordPress page builder. With over 21 million downloads and a million active installs, it is a staple for many websites looking to enhance their design and functionality. However, the recent discovery of a vulnerability underscores the importance of staying informed about potential security risks and maintaining up-to-date software.

Details About the Vulnerability:

The vulnerability in the ElementsKit Elementor Addons plugin, specifically in versions up to 3.2.0, stems from missing capability checks in the ekit_widgetarea_content function. This flaw allows unauthenticated users to view any content created using Elementor, including posts, pages, templates, drafts, and private items. Identified by the researcher known as stealthcopter, the vulnerability was publicly disclosed on July 18, 2024, and has been assigned a CVSS score of 5.4, indicating a moderate level of risk.

Risks and Potential Impacts of the Vulnerability:

The primary risk associated with this vulnerability is the unauthorized exposure of sensitive content. This can include private drafts, unpublished posts, and other restricted content that are not intended for public viewing. Such exposure can lead to privacy breaches, potentially damaging the reputation of the website and eroding user trust. While the vulnerability does not grant attackers direct control over the site, the information revealed can be exploited for further malicious activities.

How to Remediate the Vulnerability:

To mitigate the risks posed by this vulnerability, it is imperative to update the ElementsKit Elementor Addons plugin to version 3.2.1 or later, where the issue has been addressed. Website owners should also review their content and access logs for signs of unauthorized viewing or other suspicious activity. For those seeking additional security, exploring alternative plugins that offer similar functionality with enhanced security measures might be beneficial.

Overview of Previous Vulnerabilities:

Since April 13, 2021, the ElementsKit Elementor Addons plugin has been reported to have 12 previous vulnerabilities. This history highlights the ongoing need for vigilance and the importance of keeping all components of a website updated and secure.

Conclusion:

For small business owners, maintaining a secure website can be challenging, especially with the numerous responsibilities involved in running a business. However, staying on top of security vulnerabilities is crucial to protect your website, your data, and your customers' trust. Regular updates, security audits, and professional assistance when needed can help safeguard your online presence. By prioritizing website security, you not only protect your business but also ensure a safe and reliable experience for your users.

Staying Secure

Staying on top of WordPress security can feel overwhelming for small business owners without dedicated IT staff. At Your WP Guy, we exist to shoulder that burden for you. Our WordPress experts can fully audit, secure, maintain and support your site - so you can focus on growing your business with peace of mind.

Don't tackle security risks alone. Let us help you assess any impact from this vulnerability, update your plugins, and implement ongoing maintenance to avoid future threats. We treat your website like it's our own - because we know how critical it is for reaching your customers.

Get in touch for a free consultation today on making WordPress security stress-free. Call 678-995-5169 or book a call here. Our knowledgeable team is ready to help you safeguard your online presence.

ElementsKit Elementor Addons Vulnerability – Unauthenticated Information Exposure via ekit_widgetarea_content Function – CVE-2024-6455 | WordPress Plugin Vulnerability Report FAQs

Leave a Comment