Unauthenticated Attackers Can Bypass Contact Form Restriction in Element Pack Elementor Addons
CVE-2024-3927
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 22 May 2024
What is CVE-2024-3927?
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) * <= 5.6.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved