Medium severity4.3NVD Advisory· Published Apr 9, 2024· Updated Apr 8, 2026
CVE-2024-1387
CVE-2024-1387
Description
The Happy Addons for Elementor plugin for WordPress is vulnerable to unauthorized access of data due to insufficient authorization on the duplicate_thing() function in all versions up to, and including, 3.10.4. This makes it possible for attackers, with contributor-level access and above, to clone arbitrary posts (including private and password protected ones) which may lead to information exposure.
Affected products
1- cpe:2.3:a:leevio:happy_addons_for_elementor:*:*:*:*:free:wordpress:*:*Range: <=3.10.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- plugins.trac.wordpress.org/changeset/3064385/happy-elementor-addons/trunk/classes/clone-handler.phpnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/aff10d5a-a2d0-461a-b52b-a25b647eaab4nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/happy-elementor-addons/trunk/classes/clone-handler.phpnvdProduct
News mentions
0No linked articles in our index yet.