Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-2203

25
FAUCET Score

CVE-2024-2203 is a Local File Inclusion vulnerability affecting The Plus Addons for Elementor WordPress plugin, versions up to and including 5.4.1. This flaw allows authenticated attackers with contributor-level access or higher to include and execute arbitrary files on the server, potentially leading to PHP code execution, bypass of access controls, or sensitive data exposure. The vulnerability has a CVSS score of 8.8 (High), indicating a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Its EPSS score is low, suggesting a limited likelihood of exploitation in the wild. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, aligning with the typical lack of attention for most CVEs.

Impacted Technologies

VendorProductVersion(s)CPE
< 5.4.2CPE matchmatch criteria
cpe:2.3:a:posimyth:the_plus_addons_for_elementor:*:*:*:*:free:wordpress:*:*
< 5.4.2CPE matchmatch criteria
cpe:2.3:a:posimyth:the_plus_addons_for_elementor:*:*:*:*:pro:wordpress:*:*

CVSS Data

CVSS version used by this source: 3.1

6.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.59%
Probability of exploitation in next 30 days
EPSS Percentile
44.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0059 is in the 35th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

siemenspatch availablevia llm_extracted
Fixed in: 9.0
View patch

Vendor Advisories (1)

siemensllm-siemens-f5c9c98fc2cbffbf

Out-of-bounds read vulnerability in libtpms

Aug 5, 2025

References

plugins.trac.wordpress.org / changeset/3056776/the-plus-addons-for-elementor-page-builder
Patch
wordfence.com / threat-intel/vulnerabilities/id/dc7ff863-3a8e-41cd-ae20-78bb4577c16a
Third Party Advisory