Vulnerabilities > Nicheaddons > Education Addon

DATE CVE VULNERABILITY TITLE RISK
2025-02-19 CVE-2024-13854 Improper Access Control vulnerability in Nicheaddons Education Addon
The Education Addon for Elementor plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.3.1 via the naedu_elementor_template shortcode due to missing validation on a user controlled key.
network
low complexity
nicheaddons CWE-284
4.3