logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2021-24175

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2021-24175

Description:
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.
Last updated date:
04/09/2021

Reports

alt

ACTIVELY EXPLOITED

Type:
exploitation
Confidence:
HIGH
Date of publishing:
04/09/2021
Reference url to background

https://nvd.nist.gov/vuln/detail/CVE-2021-24175

Type:
exploit
Confidence:
HIGH
Date of publishing:
04/09/2021
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy