What the vulnerability does
01Description
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.
Explanation of Vulnerability in Simple Terms
Unlimited Elements For Elementor contains a path traversal vulnerability that allows authenticated users to read files outside the intended directory. An attacker with low-level site access can enumerate and access sensitive files on the server by manipulating file paths. This affects versions up to 2.0.14. Update to a version newer than 2.0.14 to resolve the issue.
What an attacker can do
Read arbitrary files on the server outside the plugin's intended directory.
Potential impact on your site
Any user with contributor or subscriber access can read sensitive files like configuration files or database backups.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities