CVE-2024-53739 HIGH

CVE-2024-53739: WordPress Cryptocurrency Widgets For Elementor plugin <= 1.6.4 - Local File Inclusion vulnerability

Vendor Cool Plugins
Product Cryptocurrency Widgets For Elementor
Weakness CWE-98 · PHP file inclusion
Published November 30, 2024
Last update April 28, 2026

CVSS base score

8.1/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Cool Plugins Cryptocurrency Widgets For Elementor cryptocurrency-widgets-for-elementor allows PHP Local File Inclusion.This issue affects Cryptocurrency Widgets For Elementor: from n/a through <= 1.6.4.

Explanation of Vulnerability in Simple Terms

02Summary

Cryptocurrency Widgets For Elementor versions 1.6.4 and earlier contain a code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code on affected sites. The vulnerability requires high attack complexity but grants full control over site data and functionality. All sites running this plugin should update immediately.

What an attacker can do

03Attacker Capabilities

Run arbitrary PHP code on the site without authentication.

Potential impact on your site

04Site Impact

Complete compromise of site data, user accounts, and server functionality if exploited.

Conditions required to exploit

05Prerequisites

Network access to the site; no user authentication required, but exploitation requires specific conditions.

Key dates

06Disclosure timeline

November 30, 2024 CVE published
April 28, 2026 Record updated