Input validation vulnerability in ElementInvader Addons for Elementor 1.2.6

The ElementInvader Addons for Elementor plugin for WordPress has a security issue in versions 1.2.6 and below. This vulnerability allows attackers who are logged in with contributor-level access or higher to include and run any files on the server, which can contain harmful PHP code. This can lead to bypassing security measures, accessing private information, or executing code, even if the files are typically considered safe, like images.

Detected in:

ElementInvader Addons for Elementor fixed vulnerable versions: >= * <= 1.2.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.