CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. It affects WordPress.
CVE
CVE-2021-4447
Severity
HIGH
CVSS
8.8
EPSS
0.46%
WordPress
Original NVD Description
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user.
Related CVEs
Other vulnerabilities affecting the same vendor(s)