First published: Wed May 22 2024(Updated: )
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
BdThemes Element Pack Elementor Addons | <=5.6.3 | |
WordPress Element Pack Pro | <5.6.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3927 has a severity rating classified as high due to its potential to allow unauthorized access to sensitive information.
To fix CVE-2024-3927, update the Element Pack Elementor Addons plugin to version 5.6.4 or later.
CVE-2024-3927 affects all versions of the Element Pack Elementor Addons plugin up to and including 5.6.3.
CVE-2024-3927 exposes a Form Submission Admin Email Bypass vulnerability, which could allow attackers to bypass form submission email controls.
The vendor for CVE-2024-3927 is Element Pack, which develops the Elementor Addons for WordPress.