First published: Tue Jul 09 2024(Updated: )
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass antispam functionality in the Form Builder widgets.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Unlimited Elements For Elementor | <1.5.113 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6171 has a high severity due to its potential for IP Address Spoofing vulnerabilities.
To resolve CVE-2024-6171, it is recommended to update the Unlimited Elements For Elementor plugin to version 1.5.113 or later.
CVE-2024-6171 affects all versions of the Unlimited Elements For Elementor plugin up to and including 1.5.112.
CVE-2024-6171 could allow unauthorized users to spoof their IP addresses, potentially leading to unauthorized access and actions on your WordPress site.
Once updated to version 1.5.113 or later, the Unlimited Elements For Elementor plugin is safe and does not have the vulnerabilities associated with CVE-2024-6171.