#VU27671 Improper Authentication in Ultimate Addons for Elementor

 

#VU27671 Improper Authentication in Ultimate Addons for Elementor

Published: May 11, 2020


Vulnerability identifier: #VU27671
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Ultimate Addons for Elementor
Software vendor:
Brainstorm Force

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can create subscriber-level users, even if registration is disabled on a WordPress site.

Note: This vulnerability is being used in conjunction with a 0-day vulnerability in Elementor PRO (SB2020051118) and allows the Elementor Pro vulnerability to be exploited, even if the site does not have user registration enabled. 


Remediation

Install updates from vendor's website.

External links