CVE-2024-8979
CVSS 3.1 Score 8.0 of 10 (high)
Details
Summary
CVE-2024-8979 is a vulnerability affecting the Essential Addons for Elementor plugin for WordPress. This issue allows authenticated attackers with Author-level access or higher to extract sensitive information, including usernames and passwords, by exploiting the 'init_content_lostpassword_user_email_controls' function in all versions up to 6.0.9. The vulnerability arises when users open password change request emails and images are not blocked by the email client, enabling the attacker to gain access to this data. This exposure poses a significant risk, particularly for Administrator accounts.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Essential Addons for Elementor Plugin
Affected Vendors
- WordPress