Input validation vulnerability in Kata Plus – Addons for Elementor – Widgets, Extensions and Templates 1.5.2

The Kata Plus plugin for WordPress has a security issue that allows hackers to inject a PHP Object. This can happen if untrusted information is used in the plugin, and it affects versions 1.5.2 and below. The vulnerability does not have a known POP chain, but if the target system has other plugins or themes installed, it could give the attacker access to delete files, get sensitive information, or run their own code.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.