CVE-2021-4447
16.10.2024, 07:15
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user.Enginsight
Vendor | Product | Version |
---|---|---|
wpdeveloper | essential_addons_for_elementor | 𝑥 < 4.6.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References