CVE-2024-37410 MEDIUM

CVE-2024-37410: WordPress PowerPack Lite for Beaver Builder plugin <= 1.3.0.3 - Local File Inclusion vulnerability

Vendor Ideabox Creations
Product PowerPack Lite for Beaver Builder
Weakness CWE-98 · PHP file inclusion
Published July 9, 2024
Last update April 28, 2026

CVSS base score

4.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in IdeaBox Creations PowerPack Lite for Beaver Builder powerpack-addon-for-beaver-builder.This issue affects PowerPack Lite for Beaver Builder: from n/a through <= 1.3.0.3.

Explanation of Vulnerability in Simple Terms

02Summary

PowerPack Lite for Beaver Builder versions up to 1.3.0.3 contain an information disclosure vulnerability. An authenticated administrator can read sensitive data they should not have access to. The vulnerability requires high-level privileges and does not affect data integrity or availability. Update to a version newer than 1.3.0.3.

What an attacker can do

03Attacker Capabilities

Read sensitive information restricted to other users or system components.

Potential impact on your site

04Site Impact

Administrators with malicious intent can access confidential data like user information or configuration details.

Conditions required to exploit

05Prerequisites

Attacker must have administrator-level access to the WordPress site.

Key dates

06Disclosure timeline

July 9, 2024 CVE published
April 28, 2026 Record updated