What the vulnerability does
01Description
Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor.This issue affects DethemeKit For Elementor: from n/a through <= 2.1.10.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Detheme DethemeKit For Elementor dethemekit-for-elementor.This issue affects DethemeKit For Elementor: from n/a through <= 2.1.10.
Explanation of Vulnerability in Simple Terms
DethemeKit For Elementor versions up to 2.1.10 lack proper authorization checks, allowing unauthenticated attackers to access sensitive information. The vulnerability exists in the plugin's handling of user requests without verifying permissions. An attacker can read data they should not have access to by making direct requests to the plugin. Site administrators should update to a version newer than 2.1.10.
What an attacker can do
Read sensitive information without authentication or proper permissions.
Potential impact on your site
Unauthorized users can access private data exposed by the plugin without logging in.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities