CVE-2021-4447

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
16/10/2024
Last modified:
10/01/2025

Description

The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:* 4.6.5 (excluding)