CVE-2024-2974 Overview
CVE-2024-2974 is a sensitive information exposure vulnerability in the Essential Addons for Elementor plugin for WordPress. The flaw affects all versions up to and including 5.9.13 and resides in the plugin's load_more AJAX function. Unauthenticated attackers can exploit the issue to retrieve private and draft posts that should not be publicly accessible. The vendor wpdeveloper addressed the flaw in version 5.9.14. The plugin is widely deployed on WordPress sites that use Elementor, expanding the potential attack surface across content-driven deployments.
Critical Impact
Unauthenticated attackers can extract private and draft post content through the load_more function, exposing unpublished editorial material and internal information.
Affected Products
- Essential Addons for Elementor (Lite) plugin for WordPress
- All versions up to and including 5.9.13
- Vendor: wpdeveloper
Discovery Timeline
- 2024-04-09 - CVE-2024-2974 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-2974
Vulnerability Analysis
The vulnerability affects the load_more AJAX handler defined in includes/Traits/Ajax_Handler.php. The handler processes pagination requests for post-listing widgets but fails to enforce authorization checks or filter results by post status. Attackers can craft AJAX requests that return posts marked as private or draft, exposing content the WordPress access model intends to restrict. The issue is categorized under [CWE-200] Exposure of Sensitive Information to an Unauthorized Actor and [CWE-922] Insecure Storage of Sensitive Information.
Root Cause
The root cause is missing authorization and improper query parameter validation in the load_more function. The handler trusts client-supplied query arguments and does not restrict returned posts to those the requester is permitted to view. As a result, WordPress core visibility rules are bypassed at the AJAX layer.
Attack Vector
Exploitation occurs over the network without authentication or user interaction. An attacker sends a crafted POST request to the WordPress admin-ajax.php endpoint invoking the load_more action with parameters that request non-public post statuses. The server responds with the underlying post data. See the Wordfence Vulnerability Report for technical details.
No verified public proof-of-concept code is available for this CVE, so no exploitation code is reproduced here.
Detection Methods for CVE-2024-2974
Indicators of Compromise
- Unusual POST requests to /wp-admin/admin-ajax.php with the action parameter set to the plugin's load_more handler from unauthenticated sources.
- AJAX responses containing post objects with post_status values of private or draft.
- High-volume request patterns targeting the load_more endpoint from a single IP or small set of IPs.
Detection Strategies
- Inventory WordPress installations and identify sites running Essential Addons for Elementor versions 5.9.13 or earlier.
- Review web server access logs for repeated admin-ajax.php requests referencing the vulnerable action parameter.
- Deploy web application firewall rules that inspect AJAX request bodies for suspicious post_status or query overrides.
Monitoring Recommendations
- Alert on unauthenticated AJAX requests that return response payloads exceeding baseline size for the load_more action.
- Monitor plugin version drift across managed WordPress fleets to detect unpatched installations.
- Correlate access logs with content management system audit events to identify anomalous access to unpublished content.
How to Mitigate CVE-2024-2974
Immediate Actions Required
- Update Essential Addons for Elementor to version 5.9.14 or later on all affected WordPress sites.
- Audit private and draft posts for evidence of unauthorized access via web server logs.
- Rotate any secrets, embargoed information, or credentials that may have been included in draft content.
Patch Information
The vendor released a fix in version 5.9.14. The patch is documented in the WordPress Plugin Changeset, which modifies the Ajax_Handler.php file to restrict the load_more function from returning non-public post statuses.
Workarounds
- If immediate patching is not feasible, disable the Essential Addons for Elementor plugin until the update can be applied.
- Restrict access to admin-ajax.php from untrusted networks using a web application firewall or reverse proxy rule.
- Remove sensitive information from draft posts until the plugin has been updated.
# Example WP-CLI command to update the plugin to the patched version
wp plugin update essential-addons-for-elementor-lite --version=5.9.14
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
