The Element Pack Elementor Addons (Header Footer,...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Aug 12, 2024 
          to the GitHub Advisory Database
          •
          Updated Jan 29, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Aug 12, 2024 
    
  
        Published to the GitHub Advisory Database
      Aug 12, 2024 
    
  
        Last updated
      Jan 29, 2025 
    
  
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to arbitrary file reads in all versions up to, and including, 5.7.2 via the SVG widget and a lack of sufficient file validation in the render_svg function. This makes it possible for authenticated attackers, with contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
References