CVE-2024-8978
CVSS 3.1 Score 5.7 of 10 (medium)
Details
Summary
CVE-2024-8978 is a newly disclosed vulnerability affecting the Essential Addons for Elementor plugin for WordPress. This Sensitive Information Exposure issue, present in versions up to 6.0.9, allows authenticated attackers with Contributor-level access or higher to extract sensitive data. By exploiting the 'init_content_register_user_email_controls' function, they can obtain usernames and passwords of users who register via the Login | Register Form widget, upon opening the email notification for successful registration. This vulnerability poses a significant risk to WordPress websites using the affected plugin and should be addressed immediately by updating to the latest version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Essential Addons for Elementor Plugin
Affected Vendors
- WordPress