The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Metrics
Affected Vendors & Products
References
History
Tue, 19 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redefiningtheweb
Redefiningtheweb pdf Generator Addon For Elementor Page Builder |
|
CPEs | cpe:2.3:a:redefiningtheweb:pdf_generator_addon_for_elementor_page_builder:*:*:*:*:*:*:*:* | |
Vendors & Products |
Redefiningtheweb
Redefiningtheweb pdf Generator Addon For Elementor Page Builder |
|
Metrics |
ssvc
|
Sat, 16 Nov 2024 03:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. | |
Title | PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Arbitrary File Download | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-11-16T03:20:45.226Z
Updated: 2024-11-19T15:14:19.116Z
Reserved: 2024-10-14T13:28:12.183Z
Link: CVE-2024-9935
Vulnrichment
Updated: 2024-11-18T21:52:50.467Z
NVD
Status : Awaiting Analysis
Published: 2024-11-16T04:15:08.103
Modified: 2024-11-18T17:11:17.393
Link: CVE-2024-9935
Redhat
No data.