CVE-2024-3927

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bdthemes:element_pack:*:*:*:*:lite:wordpress:*:*

History

08 Apr 2026, 18:21

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/modules/contact-form/module.php#L102 - () https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/modules/contact-form/module.php#L102 - Product
References () https://plugins.trac.wordpress.org/changeset/3089154 - () https://plugins.trac.wordpress.org/changeset/3089154 - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/3a703fc4-6c61-442e-a637-515e9f501575?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/3a703fc4-6c61-442e-a637-515e9f501575?source=cve - Third Party Advisory
CPE cpe:2.3:a:bdthemes:element_pack:*:*:*:*:lite:wordpress:*:*
CWE NVD-CWE-noinfo
CWE-424
First Time Bdthemes
Bdthemes element Pack

21 Nov 2024, 09:30

Type Values Removed Values Added
References () https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/modules/contact-form/module.php#L102 - () https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/modules/contact-form/module.php#L102 -
References () https://plugins.trac.wordpress.org/changeset/3089154 - () https://plugins.trac.wordpress.org/changeset/3089154 -
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/3a703fc4-6c61-442e-a637-515e9f501575?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/3a703fc4-6c61-442e-a637-515e9f501575?source=cve -
Summary
  • (es) El complemento Element Pack Elementor Addons (encabezado, pie de página, librería de plantillas, cuadrícula dinámica y carrusel, flechas remotas) para WordPress es vulnerable a la omisión de correo electrónico del administrador de envío de formularios en todas las versiones hasta la 5.6.3 incluida. Esto se debe a que el complemento no verifica adecuadamente todas las variaciones de los correos electrónicos de un administrador. Esto hace posible que los atacantes no autenticados eviten la restricción utilizando un valor + al enviar el formulario de contacto.

22 May 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-22 07:15

Updated : 2026-04-08 18:21


NVD link : CVE-2024-3927

Mitre link : CVE-2024-3927

CVE.ORG link : CVE-2024-3927


JSON object : View

Products Affected

bdthemes

  • element_pack
CWE
CWE-424

Improper Protection of Alternate Path

NVD-CWE-noinfo