Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-3927

Опубликовано: 22 мая 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bdthemes:element_pack:*:*:*:*:lite:wordpress:*:*
Версия до 5.6.4 (исключая)

EPSS

Процентиль: 66%
0.00512
Низкий

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
github
больше 1 года назад

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.

EPSS

Процентиль: 66%
0.00512
Низкий

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo