S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24358 Scanner

CVE-2021-24358 scanner - Open Redirect vulnerability in The Plus Addons for Elementor Page Builder WordPress plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24358
6.1
CVSS

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
The Plus Addons for Elementor Page Builder
AFFECTED< 4.1.10SAFE ✓≥ 4.1.10
Updated Aug 21, 2026View on NVD →
Detail

The Plus Addons for Elementor Page Builder WordPress plugin is a widely used plugin that enhances the functionality of the Elementor page builder. It adds a wide range of widgets and modules to Elementor, providing users with a seamless and efficient page building experience. With its user-friendly interface, The Plus Addons for Elementor Page Builder WordPress plugin has been widely embraced by web developers who want to create custom pages and websites with ease. 

However, recently, a vulnerability, CVE-2021-24358, was detected in this plugin. This vulnerability arises from the fact that the plugin does not validate the redirect parameter on a specifically crafted URL before redirecting the user to it, thus leading to an Open Redirect issue. The implication of this vulnerability is that an attacker can craft malicious links, which when clicked, redirect users to a phishing site or other malicious websites.

The exploitation of this vulnerability can lead to serious consequences. An attacker can use it to steal personal information, such as login credentials, sensitive data, and other personal information. In addition, they can use it to install malicious software or launch other types of cyber attacks, such as denial-of-service (DoS) attacks, which can cause significant damage to the website or the server hosting it.

In conclusion, the vulnerability detected in The Plus Addons for Elementor Page Builder WordPress plugin highlights the need for proactive security measures to protect digital assets. By using web vulnerability scanners and other security tools, web developers can easily and quickly detect and remediate vulnerabilities, protecting their websites and users from cyber threats. With the pro features of the s4e.io platform, users can access a wealth of information about vulnerabilities and threats, enhancing their overall digital security.

 

REFERENCES

Solution Advice

To protect against this vulnerability, web developers and owners can take the following precautions:

  • Install the latest updates of The Plus Addons for Elementor Page Builder WordPress plugin.
  • Set the maximum length of the redirect parameter.
  • Block any suspicious URLs using firewalls or other security tools.
  • Educate users to be aware of the risks of clicking on unknown or suspicious links.
  • Use a web vulnerability scanner to proactively identify and remediate vulnerabilities in digital assets.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.