CVE-2024-5153
Last modified
CVE-2024-5153 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzone_hash' parameter. This makes it possible for unauthenticated attackers to copy the contents of arbitrary files on the server, which can contain sensitive information, and to delete arbitrary directories, including the root WordPress directory.. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzone_hash' parameter. This makes it possible for unauthenticated attackers to copy the contents of arbitrary files on the server, which can contain sensitive information, and to delete arbitrary directories, including the root WordPress directory.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Web-Shop-Host | Startklar Elmentor Addons | <= 1.7.15 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-5153?
How severe is CVE-2024-5153?
How do I fix CVE-2024-5153?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-51524Permission control vulnerability in the Wi-Fi module Impact:…5.5
- CVE-2024-51525Permission control vulnerability in the clipboard module Imp…5.5
- CVE-2024-51526Permission control vulnerability in the hidebug module Impac…5.5
- CVE-2024-51527Permission control vulnerability in the Gallery app Impact: …5.5
- CVE-2024-51528Vulnerability of improper log printing in the Super Home Scr…5.5
- CVE-2024-51529Data verification vulnerability in the battery module Impact…5.5
- CVE-2024-51530LaunchAnywhere vulnerability in the account module Impact: S…5.5
- CVE-2024-51532Dell PowerStore contains an Improper Neutralization of Argum…7.1
- CVE-2024-51534Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.…7.1
- CVE-2024-51539The Dell Secure Connect Gateway (SCG) Application and Applia…2.3
- CVE-2024-5154A flaw was found in cri-o. A malicious container can create …8.1
- CVE-2024-51540Dell ECS, versions prior to 3.8.1.3 contains an arithmetic o…6.5
Are you affected by CVE-2024-5153?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
