What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elementor Page builder allows PHP Local File Inclusion.This issue affects Void Elementor Post Grid Addon for Elementor Page builder: from n/a through 2.3.
Explanation of Vulnerability in Simple Terms
02Summary
The Void Elementor Post Grid Addon for Elementor allows authenticated users to read arbitrary files from the server through a path traversal vulnerability. An attacker with low-level site access can bypass directory restrictions and access sensitive files outside the intended scope. The vulnerability requires network access and low privileges but does not require user interaction.
What an attacker can do
03Attacker Capabilities
Read arbitrary files from the server, including configuration files and other sensitive data.
Potential impact on your site
04Site Impact
Sensitive files like database credentials, API keys, or configuration data could be exposed to authenticated users.
Conditions required to exploit
05Prerequisites
Attacker must have low-level authenticated access to the site (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
August 19, 2024
CVE published
April 28, 2026
Record updated