Security Advisory
CVE-2024-7063
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The ElementsKit Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.6 via the render_raw function. This can allow authenticated attackers, with Contributor-level permissions and above, to extract sensitive data including private, future, and draft posts.