Output validation vulnerability in Themesflat Addons For Elementor 2.0.0

The Themesflat Addons For Elementor plugin for WordPress is vulnerable to a type of attack called PHP Object Injection in versions 2.0.0 and earlier. This type of attack occurs when untrusted input is deserialized through the ‘settings’ parameter which is retrieved from the tf_product_filter nopriv AJAX action. This vulnerability allows unauthenticated attackers to inject a PHP Object, which could allow them to delete files, retrieve sensitive data, or execute code on the system.

Detected in:

Themesflat Addons For Elementor open vulnerable versions: >= * <= 2.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.