CVE-2024-50453 HIGH

CVE-2024-50453: WordPress The Pack Elementor addons plugin <= 2.0.9 - Local File Inclusion vulnerability

Vendor Webangon
Product The Pack Elementor addons
Weakness CWE-23
Published October 28, 2024
Last update May 12, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusion.This issue affects The Pack Elementor addons: from n/a through <= 2.0.9.

Explanation of Vulnerability in Simple Terms

02Summary

The Pack Elementor addons through version 2.0.9 contains a path traversal vulnerability that allows authenticated users with low privileges to read, modify, or delete files on the server. The vulnerability requires high attack complexity but grants full access to sensitive data and site functionality. All versions up to 2.0.9 are affected.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete files on the server including sensitive configuration and database files.

Potential impact on your site

04Site Impact

An attacker with a basic user account can compromise your entire site by accessing config files, modifying content, or deleting critical data.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account (e.g., subscriber or contributor role) on the site.

Key dates

06Disclosure timeline

October 28, 2024 CVE published
May 12, 2026 Record updated

Related vulnerabilities

08Related CVE