What the vulnerability does
01Description
Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusion.This issue affects The Pack Elementor addons: from n/a through <= 2.0.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusion.This issue affects The Pack Elementor addons: from n/a through <= 2.0.9.
Explanation of Vulnerability in Simple Terms
The Pack Elementor addons through version 2.0.9 contains a path traversal vulnerability that allows authenticated users with low privileges to read, modify, or delete files on the server. The vulnerability requires high attack complexity but grants full access to sensitive data and site functionality. All versions up to 2.0.9 are affected.
What an attacker can do
Read, modify, or delete files on the server including sensitive configuration and database files.
Potential impact on your site
An attacker with a basic user account can compromise your entire site by accessing config files, modifying content, or deleting critical data.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or contributor role) on the site.
Key dates
External resources
Related vulnerabilities