High severity8.8NVD Advisory· Published Oct 16, 2024· Updated Jun 17, 2026
CVE-2021-4447
CVE-2021-4447
Description
The Essential Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to and including 4.6.4 due to a lack of restrictions on who can add a registration form and a custom registration role to an Elementor created page. This makes it possible for attackers with access to the Elementor page builder to create a new registration form that defaults to the user role being set to administrator and subsequently register as an administrative user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:wpdeveloper:essential_addons_for_elementor:*:*:*:*:lite:wordpress:*:*Range: <4.6.5
- Range: <=4.6.4
- wpdevteam/Essential Addons for Elementor – Popular Elementor Templates & Widgetsv5Range: 0
Patches
Vulnerability mechanics
References
2- www.wordfence.com/threat-intel/vulnerabilities/id/be098ee9-b749-4908-85e8-e717d019609anvdThird Party Advisory
- plugins.trac.wordpress.org/changesetnvdProduct
News mentions
0No linked articles in our index yet.