CVE-2024-3927: Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.3 - Form Submission Admin Email Bypass
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3927?
CVE-2024-3927 has a severity rating classified as high due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2024-3927?
To fix CVE-2024-3927, update the Element Pack Elementor Addons plugin to version 5.6.4 or later.
What versions are affected by CVE-2024-3927?
CVE-2024-3927 affects all versions of the Element Pack Elementor Addons plugin up to and including 5.6.3.
What vulnerability does CVE-2024-3927 expose?
CVE-2024-3927 exposes a Form Submission Admin Email Bypass vulnerability, which could allow attackers to bypass form submission email controls.
Who is the vendor for CVE-2024-3927?
The vendor for CVE-2024-3927 is Element Pack, which develops the Elementor Addons for WordPress.