Description
WordPress Plugin Elements For Elementor is prone to a local file inclusion vulnerability because it fails to sufficiently verify user-supplied input. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks. WordPress Plugin Elements For Elementor version 2.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.2 or latest
References
Related Vulnerabilities
WordPress Plugin Newsletter-Send awesome emails from WordPress Cross-Site Scripting (4.6.0)
WordPress Plugin Booking Calendar Multiple Vulnerabilities (6.2)
WordPress Plugin Acobot Live Chat & Contact Form Multiple Vulnerabilities (2.0)
WordPress Plugin Woocommerce-Recent Purchases Local File Inclusion (1.0.1)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-4281)