🔙 목록으로 돌아가기

CVE-2021-24175: The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass

TitleThe Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass
Authorpussycat0x
SeverityCritical
ImpactUnauthenticated attackers can bypass authentication, gain administrator access, and create elevated privilege accounts even when registration is disabled, leading to complete WordPress site takeover.
RemediationFixed in 4.1.7
CVSS Score9.8
EPSS Score0.80698
CVE IDCVE-2021-24175
CWE IDCWE-287
Fofa Querybody="/wp-content/plugins/the-plus-addons-for-elementor-page-builder/"
Tags cve cve2021 wordpress wp-theme wpscan elementor plus-addons passive vkev vuln

🔍 Vulnerability Description

The Plus Addons for Elementor plugin (before version 4.1.7) allowed attackers to bypass authentication, gain admin access, and create accounts with elevated roles, even when registration was disabled and the Login widget was inactive.

🌐 HTTP Request

GET /wp-content/plugins/the-plus-addons-for-elementor-page-builder/readme.txt HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (watchTowr; Windows NT 10.0; Win64; x64; rv:84.0) Gecko/20100101 Firefox/84.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24175.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-24175.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A