CVE-2024-8978

CVSS 3.1 Score 5.7 of 10 (medium)

Details

Published Nov 15, 2024
CWE ID 200

Summary

CVE-2024-8978 is a newly disclosed vulnerability affecting the Essential Addons for Elementor plugin for WordPress. This Sensitive Information Exposure issue, present in versions up to 6.0.9, allows authenticated attackers with Contributor-level access or higher to extract sensitive data. By exploiting the 'init_content_register_user_email_controls' function, they can obtain usernames and passwords of users who register via the Login | Register Form widget, upon opening the email notification for successful registration. This vulnerability poses a significant risk to WordPress websites using the affected plugin and should be addressed immediately by updating to the latest version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Essential Addons for Elementor Plugin

Affected Vendors

  • WordPress