Input validation vulnerability in The Plus Addons for Elementor Page Builder 5.5.6

The Plus Addons plugin for WordPress is at risk for a type of attack called Local File Inclusion. This vulnerability affects all versions up to 5.5.4 and can be exploited through a widget called Dynamic Smart Showcase. This allows attackers with Contributor-level access or higher to include and run any files on the server, potentially giving them access to sensitive information or allowing them to run malicious code. This can happen even if the files are supposedly safe, like images.

Detected in:

The Plus Addons for Elementor fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.