CVE-2021-24359

CVE-2021-24359: The Plus Addons for Elementor Page Builder < 4.1.11 - Arbitrary Reset Pwd Email Sending

Vendor Unknown
Product The Plus Addons for Elementor Page Builder
Weakness CWE-284
Published June 14, 2021
Last update August 3, 2024

CVSS base score

What the vulnerability does

01Description

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password email to a registered user on behalf of the WordPress site. Such issue could be chained with an open redirect (CVE-2021-24358) in version below 4.1.10, to include a crafted password reset link in the email, which would lead to an account takeover.

Key dates

02Disclosure timeline

June 14, 2021 CVE published
August 3, 2024 Record updated

Related vulnerabilities

04Related CVE