The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6.2 via the 'duplicate' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.
History

Thu, 06 Mar 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wpxpro
Wpxpro xpro Addons For Elementor
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:wpxpro:xpro_addons_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Wpxpro
Wpxpro xpro Addons For Elementor

Wed, 08 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jan 2025 06:45:00 +0000

Type Values Removed Values Added
Description The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6.2 via the 'duplicate' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract potentially sensitive data from draft, scheduled (future), private, and password protected posts.
Title 140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6.2 - Authenticated (Contributor+) Post Disclosure via Post Duplication
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-01-08T06:41:38.596Z

Updated: 2025-01-08T14:36:36.202Z

Reserved: 2024-12-12T17:55:55.047Z

Link: CVE-2024-12584

cve-icon Vulnrichment

Updated: 2025-01-08T14:36:30.746Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-08T07:15:26.833

Modified: 2025-03-06T20:57:36.280

Link: CVE-2024-12584

cve-icon Redhat

No data.