CVE-2021-24359
The Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email Sending
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password email to a registered user on behalf of the WordPress site. Such issue could be chained with an open redirect (CVE-2021-24358) in version below 4.1.10, to include a crafted password reset link in the email, which would lead to an account takeover.
El WordPress Plus Addons para Elementor Page Builder versiones anteriores a 4.1.11, no comprobaba apropiadamente que un usuario que pedía el restablecimiento de la contraseña era el usuario legítimo, permitiendo a un atacante enviar un correo electrónico de restablecimiento de contraseña arbitrario a un usuario registrado en nombre del sitio de WordPress. Este problema podría ser encadenado con un redireccionamiento abierto (CVE-2021-24358) en la versión por debajo de 4.1.10, para incluir un enlace de restablecimiento de contraseña diseñado en el correo electrónico, que podría conllevar a una toma de control de la cuenta
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-14 CVE Reserved
- 2021-05-31 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-284: Improper Access Control
- CWE-287: Improper Authentication
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/486b82d1-30d4-44d2-9542-f33e3f149e92 | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://theplusaddons.com/changelog | 2022-10-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Posimyth Search vendor "Posimyth" | The Plus Addons For Elementor Search vendor "Posimyth" for product "The Plus Addons For Elementor" | < 4.1.11 Search vendor "Posimyth" for product "The Plus Addons For Elementor" and version " < 4.1.11" | wordpress |
Affected
|