Beta

Report

Qi Addons For Elementor <= 1.7.2 is vulnerable to Authenticated (Contributor+) Local File Inclusion vulnerability

Contributor
Published
2024-06-06

The Qi Addons For Elementor plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.7.2 via the 'behavior' attributes found in the qi_addons_for_elementor_blog_list shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to include remote files on the server, resulting in code execution. Please note that this requires an attacker to create a non-existent directory or target an instance where file_exists won't return false with a non-existent directory in the path, in order to successfully exploit.

CVSS

Score:8.5

Severity:High

Version: 1.7.2

There is a patch available in v1.7.3 and we strongly recommend you update to this version as soon as possible.