CVE-2024-8979

CVSS 3.1 Score 8.0 of 10 (high)

Details

Published Nov 15, 2024
CWE ID 200

Summary

CVE-2024-8979 is a vulnerability affecting the Essential Addons for Elementor plugin for WordPress. This issue allows authenticated attackers with Author-level access or higher to extract sensitive information, including usernames and passwords, by exploiting the 'init_content_lostpassword_user_email_controls' function in all versions up to 6.0.9. The vulnerability arises when users open password change request emails and images are not blocked by the email client, enabling the attacker to gain access to this data. This exposure poses a significant risk, particularly for Administrator accounts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Essential Addons for Elementor Plugin

Affected Vendors

  • WordPress