Ultra Addons Lite for Elementor Information Exposure Vulnerability
Vulnerability
A vulnerability allowing information exposure has been identified in the Ultra Addons Lite for Elementor WordPress plugin, affecting all versions through 1.1.8. The issue arises from the 'ut_elementor' shortcode, which lacks proper restrictions on the posts that can be included. This flaw enables authenticated attackers with Contributor-level access or higher to access and extract data from password-protected, private, or draft posts that should otherwise be off-limits.
Impact
Exploitation of this vulnerability could lead to unauthorized access to restricted post data, including content from password-protected, private, or draft posts that the attacker should not have access to.
Remediation
Users can update to Ultra Addons Lite for Elementor version 1.1.9 or later to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
