Record summary

CVE-2021-24358 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

The Plus Addons for Elementor Page Builder

CVE List4.1.10 to < 4.1.10affected

Nuclei templates

1
ProjectDiscoveryMEDIUMPlus Addons for Elementor Page Builder < 4.1.10 - Open RedirectCVSS 6.1

WordPress Plus Addons for Elementor Page Builder before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an open redirect issue.

Impact

This vulnerability can be exploited by attackers to trick users into visiting malicious websites, leading to potential phishing attacks or the execution of other malicious activities.

Remediation

Upgrade Plus Addons for Elementor Page Builder to version 4.1.10 or later to mitigate the vulnerability.

WeaknessesCWE-601
AuthorsdhiyaneshDk
Template tagscve2021cvewpwpscanwordpressredirectwp-pluginelementorposimythvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:posimyth:the_plus_addons_for_elementor:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3