CVE-2021-24358
The Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirect
Record summary
CVE-2021-24358 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
The Plus Addons for Elementor Page Builder | CVE List | 4.1.10 to < 4.1.10 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMPlus Addons for Elementor Page Builder < 4.1.10 - Open RedirectCVSS 6.1
WordPress Plus Addons for Elementor Page Builder before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an open redirect issue.
Impact
This vulnerability can be exploited by attackers to trick users into visiting malicious websites, leading to potential phishing attacks or the execution of other malicious activities.
Remediation
Upgrade Plus Addons for Elementor Page Builder to version 4.1.10 or later to mitigate the vulnerability.
Source: ProjectDiscovery