The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the 'ut_elementor' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
History

Wed, 08 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Uncodethemes
Uncodethemes ultra Addons Lite For Elementor
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:uncodethemes:ultra_addons_lite_for_elementor:*:*:*:*:*:wordpress:*:*
Vendors & Products Uncodethemes
Uncodethemes ultra Addons Lite For Elementor

Wed, 08 Apr 2026 17:45:00 +0000


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Feb 2025 08:30:00 +0000

Type Values Removed Values Added
Description The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the 'ut_elementor' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, or draft posts that they should not have access to.
Title Ultra Addons Lite for Elementor <= 1.1.8 - Authenticated (Contributor+) Restricted Post Disclosure
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:49:59.882Z

Reserved: 2025-02-04T19:00:12.219Z

Link: CVE-2024-13832

cve-icon Vulnrichment

Updated: 2025-02-28T13:49:41.010Z

cve-icon NVD

Status : Modified

Published: 2025-02-28T09:15:10.570

Modified: 2026-04-08T18:20:18.777

Link: CVE-2024-13832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.