What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme ShopBuilder – Elementor WooCommerce Builder Addons shopbuilder.This issue affects ShopBuilder – Elementor WooCommerce Builder Addons: from n/a through <= 2.1.12.
Explanation of Vulnerability in Simple Terms
02Summary
ShopBuilder for Elementor contains a flaw that allows authenticated users with low privileges to read sensitive data they should not access. The vulnerability stems from improper access controls on data retrieval functions. An attacker with a basic user account can view confidential information without additional interaction. Site administrators should update to a patched version immediately.
What an attacker can do
03Attacker Capabilities
Read sensitive data accessible only to higher-privilege users or administrators.
Potential impact on your site
04Site Impact
Customer data, admin settings, or other confidential information may be exposed to low-privilege users.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site (e.g., subscriber or customer).
Key dates
06Disclosure timeline
July 9, 2024
CVE published
April 28, 2026
Record updated