T
he Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possible for authenticated attackers, with Author-level access and above, to create and query a malicious post title, resulting in slowing server resources.
References
Configurations
History
21 Nov 2024, 09:49
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/trunk/includes/class-premium-template-tags.php#L1676 - Product | |
| References | () https://plugins.trac.wordpress.org/changeset/3110991/ - Patch | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/3c59d95a-b7f1-4a04-bbf4-bab2c42d6d75?source=cve - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 3.1 |
05 Jul 2024, 17:22
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| CWE | CWE-1333 | |
| CPE | cpe:2.3:a:leap13:premium_addons_for_elementor:*:*:*:*:*:wordpress:*:* | |
| First Time |
Leap13
Leap13 premium Addons For Elementor |
|
| References | () https://plugins.trac.wordpress.org/browser/premium-addons-for-elementor/trunk/includes/class-premium-template-tags.php#L1676 - Product | |
| References | () https://plugins.trac.wordpress.org/changeset/3110991/ - Patch | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/3c59d95a-b7f1-4a04-bbf4-bab2c42d6d75?source=cve - Third Party Advisory |
05 Jul 2024, 12:55
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
04 Jul 2024, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-07-04 09:15
Updated : 2024-11-21 09:49
NVD link : CVE-2024-6434
Mitre link : CVE-2024-6434
CVE.ORG link : CVE-2024-6434
JSON object : View
Products Affected
CWE
CWE-1333
Inefficient Regular Expression Complexity