CVE-2021-4447

The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:*

History

No history.

Information

Published : 2024-10-16 07:15

Updated : 2025-01-10 14:39


NVD link : CVE-2021-4447

Mitre link : CVE-2021-4447

CVE.ORG link : CVE-2021-4447


JSON object : View

Products Affected

wpdeveloper

  • essential_addons_for_elementor
CWE
CWE-862

Missing Authorization