← back
CVE-2024-5153criticalCWE-22

Startklar Elementor Addons <= 1.7.15 - Unauthenticated Path Traversal to Arbitrary Directory Deletion

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.1epss 1.0%
from disclosure to weapon583 days
Published on NVDJun 6
1st PoC+583d
exploitation probability
1.0%top 41% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Startklar Elementor Addons plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.15 via the 'dropzone_hash' parameter. This makes it possible for unauthenticated attackers to copy the contents of arbitrary files on the server, which can contain sensitive information, and to delete arbitrary directories, including the root WordPress directory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.