CVE-2021-24175 describes a critical authentication bypass vulnerability in the Plus Addons for Elementor Page Builder WordPress plugin, affecting versions prior to 4.1.7. This flaw allows unauthenticated attackers to log in as any user, including administrators, simply by providing a username, and to create accounts with arbitrary roles, even when registration is disabled or the login widget is inactive. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, the vulnerability poses a severe risk of complete compromise (Confidentiality, Integrity, Availability). While there are no Metasploit modules or ExploitDB entries, Nuclei templates exist for detection, and the vulnerability was actively exploited by malicious actors, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.7CPE matchmatch criteria | cpe:2.3:a:posimyth:the_plus_addons_for_elementor:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.