CVE-2024-24934
About
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.
Rainforest analyst review
Elementor's Website Builder can be coaxed into using attacker-supplied input in a file-system call, letting a request walk outside the intended directory. Because Elementor is one of the most widely installed WordPress builders on the planet, the raw population of affected sites is enormous, which is what pulls the score toward the top.
But the exploitation profile is more demanding than the headline suggests. This one needs some level of authenticated access and the attack is rated hard to pull off, so it isn't the indiscriminate one-request smash that unauthenticated plugin bugs are. That combination means it's more likely used by an attacker who already has a low-privilege account, or as a step in a chain, than by a botnet spraying every install.
We handle this as an inventory-plus-context problem. Yes, we map which sites carry Elementor and at what version, but we deliberately rank it against its preconditions rather than its 8.5: sites that allow low-privilege user registration and expose the affected path deserve priority, while locked-down single-author installs can wait for the normal update cycle. The value we add is separating the scary install count from the far smaller set that is actually reachable and abusable.
References
Related CVEs
Frequently asked questions
What is CVE-2024-24934?
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.
How severe is CVE-2024-24934?
CVE-2024-24934 carries a CVSS 3.1 base score of 8.5, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 93 out of 100, in the critical band.
How is CVE-2024-24934 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity High, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2024-24934?
Public advisories list the following as affected: website builder. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2024-24934?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
