PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 24, 2025

The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24175
9.8
CVSS

The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious actors to bypass authentication, allowing unauthenticated users to log in as any user (including admin) by just providing the related username, as well as create accounts with arbitrary roles, such as admin. These issues can be exploited even if registration is disabled, and the Login widget is not active.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
The Plus Addons for Elementor Page Builder
AFFECTED< 4.1.7SAFE ✓≥ 4.1.7
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication Bypass CVE-2021-24175 Scanner | S4E