← Back to CVEs
CVE-2021-24175
CRITICAL9.8
Description
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published4/5/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
posimyth:the_plus_addons_for_elementor
Weaknesses (CWE)
CWE-287CWE-287
References
https://posimyth.ticksy.com/ticket/2713734/(contact@wpscan.com)
https://wpscan.com/vulnerability/c311feef-7041-4c21-9525-132b9bd32f89(contact@wpscan.com)
https://www.wordfence.com/blog/2021/03/critical-0-day-in-the-plus-addons-for-elementor-allows-site-takeover/(contact@wpscan.com)
https://posimyth.ticksy.com/ticket/2713734/(af854a3a-2127-422b-91ae-364da2661108)
https://wpscan.com/vulnerability/c311feef-7041-4c21-9525-132b9bd32f89(af854a3a-2127-422b-91ae-364da2661108)
https://www.wordfence.com/blog/2021/03/critical-0-day-in-the-plus-addons-for-elementor-allows-site-takeover/(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.