The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass antispam functionality in the Form Builder widgets.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-47311 The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 1.5.112 due to insufficient IP address validation and/or use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to bypass antispam functionality in the Form Builder widgets.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2024-08-01T21:33:04.694Z

Reserved: 2024-06-19T17:46:41.014Z

Link: CVE-2024-6171

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:04.694Z

cve-icon NVD

Status : Modified

Published: 2024-07-09T05:15:14.140

Modified: 2024-11-21T09:49:06.920

Link: CVE-2024-6171

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses