The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.11 did not properly check that a user requesting a password reset was the legitimate user, allowing an attacker to send an arbitrary reset password email to a registered user on behalf of the WordPress site. Such issue could be chained with an open redirect (CVE-2021-24358) in version below 4.1.10, to include a crafted password reset link in the email, which would lead to an account takeover.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-06-14T13:37:14

Updated: 2024-08-03T19:28:23.838Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24359

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-06-14T14:15:08.997

Modified: 2022-10-25T23:43:21.477

Link: CVE-2021-24359

cve-icon Redhat

No data.