CRITICAL

CVE-2021-24175

CVSS v3

9.8

CRITICAL

EPSS Score

90.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.

Technical details

Published
4/5/2021

Frequently asked questions

What is CVE-2021-24175?

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.

Is CVE-2021-24175 actively exploited?

Active exploitation of CVE-2021-24175 has not been confirmed. The EPSS score is 90.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-24175?

CVE-2021-24175 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-24175 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.