CVE-2021-24175
critical · 9.8A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.
9.8
CVSS
14.5%
EPSS (exploit prob.)
96th
EPSS percentile
2021-04-05
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| posimyth | the_plus_addons_for_elementor | < 4.1.7 |
Check a specific version with /api/v1/cve/match.
References
- https://posimyth.ticksy.com/ticket/2713734/
- https://wpscan.com/vulnerability/c311feef-7041-4c21-9525-132b9bd32f89
- https://www.wordfence.com/blog/2021/03/critical-0-day-in-the-plus-addons-for-elementor-allows-site-takeover/
- https://posimyth.ticksy.com/ticket/2713734/
- https://wpscan.com/vulnerability/c311feef-7041-4c21-9525-132b9bd32f89
- https://www.wordfence.com/blog/2021/03/critical-0-day-in-the-plus-addons-for-elementor-allows-site-takeover/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-24175