Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders <= 6.0.9 - Authenticated (Author+) Sensitive Information Exposure to Privilege Escalation
Published Nov 15, 2024
8.0
HIGHCVSS 3.1
EPSS 0.50%
Description
The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_lostpassword_user_email_controls' function. This makes it possible for authenticated attackers, with Author-level access and above, to extract sensitive data including usernames and passwords of any user, including Administrators, as long as that user opens the email notification for a password change request and images are not blocked by the email client.
Affected products
- Vendor Wpdevteam Product Essential Addons for Elementor – Popular Elementor Templates & Widgets Defaultunaffected
- Version 0StatusaffectedConstraints<=6.0.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Wpdevteam | Essential Addons for Elementor – Popular Elementor Templates & Widgets | unaffected |
|
- < 6.0.10
-
- Version 0StatusaffectedConstraints<=6.0.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Wpdeveloper | Essential Addons for Elementor | unaffected |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/trunk/includes/Elements/Login_Register.php#L2440 Product
- https://plugins.trac.wordpress.org/changeset/3188634/ Product
- https://www.wordfence.com/threat-intel/vulnerabilities/id/34d09086-be33-40cf-b5bf-d6c03cf0b68a?source=cve Third Party Advisory
Change history (0)
No recorded changes yet.