CVE-2024-4346 is a critical arbitrary file deletion vulnerability affecting all versions up to and including 1.7.13 of the Startklar Elementor Addons plugin for WordPress. This flaw, stemming from insufficient validation of uploaded file paths, allows unauthenticated attackers to delete arbitrary files, including sensitive ones like wp-config.php. With a CVSS score of 9.1 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to site takeover and remote code execution. While there is no known active exploitation, public exploit code, or significant community discussion at this time, its high EPSS score indicates a notable potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Wshberlin | Startklar Elementor Addons | >= 0, <= 1.7.13CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.