The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to include the contents of arbitrary PHP files on the server, which may expose sensitive information.
Project Subscriptions
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-17115 | The Elementor Addon Elements plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.12.12 via the render function. This makes it possible for authenticated attackers, with contributor access or higher, to include the contents of arbitrary PHP files on the server, which may expose sensitive information. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Elementor Addon Elements <= 1.12.12 - Directory Traversal to Local File Inclusion |
Wed, 25 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpvibes
Wpvibes anywhere Elementor |
|
| CPEs | cpe:2.3:a:wpvibes:anywhere_elementor:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpvibes
Wpvibes anywhere Elementor |
|
| Metrics |
ssvc
|
Fri, 17 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Webtechstreet
Webtechstreet elementor Addon Elements |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:webtechstreet:elementor_addon_elements:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Webtechstreet
Webtechstreet elementor Addon Elements |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:41:19.074Z
Reserved: 2024-02-08T18:18:46.714Z
Link: CVE-2024-1358
Updated: 2024-08-01T18:33:25.444Z
Status : Modified
Published: 2024-03-13T16:15:19.870
Modified: 2026-04-08T17:18:19.100
Link: CVE-2024-1358
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD