CVE-2024-6824: CWE-862 Missing Authorization in leap13 Premium Addons for Elementor
The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'check_temp_validity' and 'update_template_title' functions in all versions up to, and including, 4.10.38. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary content and update post and page titles.
CVE-2024-6824: CWE-862 Missing Authorization in leap13 Premium Addons for Elementor
Description
The Premium Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'check_temp_validity' and 'update_template_title' functions in all versions up to, and including, 4.10.38. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary content and update post and page titles.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- Wordfence
- Date Reserved
- 2024-07-16T23:15:15.278Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 699f6c0cb7ef31ef0b55f5e5
Added to database: 2/25/2026, 9:39:24 PM
Last updated: 2/25/2026, 9:41:43 PM
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
CVE-2024-3599: CWE-862 Missing Authorization in wpeka-club WP Cookie Consent ( for GDPR, CCPA & ePrivacy )
MediumCVE-2024-3598: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in wpmet ElementsKit Pro
MediumCVE-2024-3597: CWE-601 URL Redirection to Untrusted Site ('Open Redirect') in recorp Export WP Page to Static HTML/CSS
HighCVE-2024-3595: CWE-80 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in pure-chat Pure Chat – Live Chat Plugin & More!
MediumCVE-2024-3593: CWE-352 Cross-Site Request Forgery (CSRF) in SevenSpark UberMenu
HighActions
Need more coverage?
Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.