CVE-2024-24844
7.5IdeaBox Creations · PowerPack Pro for Elementor
A missing authorization vulnerability in IdeaBox Creations PowerPack Pro for Elementor allows unauthenticated attackers to exploit incorrectly configured access control security levels.
Executive summary
A missing authorization vulnerability in the PowerPack Pro for Elementor plugin exposes users to potential service disruption due to unauthenticated access control bypass.
Vulnerability
This is a missing authorization flaw (CWE-862) occurring within the plugin configuration, which allows unauthenticated remote attackers to trigger unauthorized actions due to improper access control validation.
Business impact
The exploitation of this vulnerability can lead to unauthorized configuration changes or service denial, potentially resulting in site instability or loss of administrative control over the plugin settings. Given the CVSS score of 7.5, this high severity flaw poses a significant risk to the availability and integrity of WordPress environments that rely on this plugin for site building.
Remediation
Immediate Action: Update the PowerPack Pro for Elementor plugin to version 2.10.8 or later to resolve the underlying authorization defect.
Proactive Monitoring: Review web server and WordPress audit logs for suspicious requests targeting plugin settings or unusual administrative activity from unauthorized IP addresses.
Compensating Controls: Deploy a Web Application Firewall with rules configured to block unauthorized access attempts to plugin management endpoints until the patch is successfully applied.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant security risk because it allows unauthenticated attackers to bypass intended access restrictions. System administrators should prioritize updating the PowerPack Pro for Elementor plugin to version 2.10.8 or higher immediately to eliminate the exposure. Failure to patch may allow attackers to manipulate plugin settings, which could lead to wider site compromise or operational disruption.
Sources
Originally found and disclosed by Dave Jong | Patchstack Threat Intelligence, per the CVE Program record.