ZeroHour

CVE-2024-6434

CVSS 3.1
4.3 medium
EPSS
<1%p46
Published
()
Modified
Description

The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possible for authenticated attackers, with Author-level access and above, to create and query a malicious post title, resulting in slowing server resources.

Vendors
leap13
Products
premium addons for elementor
Ecosystems
WordPress
Weakness
CWE-400, CWE-1333
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

In the news

No ingested article mentions this CVE yet.