Unrated severityNVD Advisory· Published Aug 8, 2024· Updated Apr 8, 2026
Premium Addons for Elementor <= 4.10.38 - Missing Authorization to Authenticated (Contributor+) Arbitrary Content Deletion and Arbitrary Title Update
CVE-2024-6824
Description
The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'check_temp_validity' and 'update_template_title' functions in all versions up to, and including, 4.10.38. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary content and update post and page titles.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=4.10.38
- leap13/Premium Addons for Elementor – Powerful Elementor Templates & Widgetsv5Range: 0
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/browser/premium-addons-for-elementor/trunk/includes/addons-integration.phpmitre
- plugins.trac.wordpress.org/browser/premium-addons-for-elementor/trunk/includes/addons-integration.phpmitre
- plugins.trac.wordpress.org/changeset/3131564/mitre
- www.wordfence.com/threat-intel/vulnerabilities/id/b2840b9e-1baf-460c-ba11-43e4279ece27mitre
News mentions
0No linked articles in our index yet.