Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-3927

Опубликовано: 22 мая 2024
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bdthemes:element_pack:*:*:*:*:lite:wordpress:*:*
Версия до 5.6.4 (исключая)

EPSS

Процентиль: 36%
0.00425
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-424
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
github
больше 2 лет назад

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.

EPSS

Процентиль: 36%
0.00425
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-424
NVD-CWE-noinfo