Lucene search

K
wpvulndbWpvulndbWPVDB-ID:6A30528E-47D5-46B6-B553-C732CB4D255F
HistoryNov 16, 2023 - 12:00 a.m.

Elementor Addon Elements < 1.12.8 - Unauthenticated Post ID/Tile Disclosure

2023-11-1600:00:00
wpscan.com
12
plugin ajax_eae_post_data function unauthenticated users arbitrary posts pages draft private ids tiles

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

28.6%

Description The plugin does not have authorisation in its ajax_eae_post_data function, allowing unauthenticated users to retrieve arbitrary posts/pages (such as draft, private etc) IDs and tiles

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

28.6%

Related for WPVDB-ID:6A30528E-47D5-46B6-B553-C732CB4D255F