CVE-2024-8978

The Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.0.9 via the 'init_content_register_user_email_controls' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including usernames and passwords of any users who register via the Login | Register Form widget, as long as that user opens the email notification for successful registration.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:*

History

19 Nov 2024, 17:04

Type Values Removed Values Added
First Time Wpdeveloper essential Addons For Elementor
Wpdeveloper
CPE cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:*
References () https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/trunk/includes/Elements/Login_Register.php#L2220 - () https://plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/trunk/includes/Elements/Login_Register.php#L2220 - Product
References () https://plugins.trac.wordpress.org/changeset/3188634/ - () https://plugins.trac.wordpress.org/changeset/3188634/ - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/baae8fb9-b87c-4f61-88da-871c4c83615b?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/baae8fb9-b87c-4f61-88da-871c4c83615b?source=cve - Third Party Advisory
CWE NVD-CWE-noinfo

15 Nov 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) Los complementos Essential Addons for Elementor – Best Elementor Addon, Templates, Widgets, Kits & WooCommerce Builders para WordPress son vulnerables a la exposición de información confidencial en todas las versiones hasta la 6.0.9 incluida a través de la función 'init_content_register_user_email_controls'. Esto hace posible que los atacantes autenticados, con acceso de nivel de colaborador y superior, extraigan datos confidenciales, incluidos los nombres de usuario y las contraseñas de cualquier usuario que se registre a través del widget Formulario de inicio de sesión | Registro, siempre que ese usuario abra la notificación por correo electrónico para el registro exitoso.

15 Nov 2024, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 10:15

Updated : 2024-11-19 17:04


NVD link : CVE-2024-8978

Mitre link : CVE-2024-8978

CVE.ORG link : CVE-2024-8978


JSON object : View

Products Affected

wpdeveloper

  • essential_addons_for_elementor
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor