The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-10-16 07:15
Updated : 2025-01-10 14:39
NVD link : CVE-2021-4447
Mitre link : CVE-2021-4447
CVE.ORG link : CVE-2021-4447
JSON object : View
Products Affected
wpdeveloper
- essential_addons_for_elementor
CWE
CWE-862
Missing Authorization
