Description
WordPress Plugin Ultimate Addons for Elementor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently create subscriber-level users, even if registration is disabled. WordPress Plugin Ultimate Addons for Elementor version 1.24.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.24.2 or latest
References
Related Vulnerabilities
Artifactory Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-10036)
WordPress Plugin Parsian Bank Woocommerce Cross-Site Scripting (1.0)
ownCloud Improper Privilege Management Vulnerability (CVE-2021-35946)
WordPress Plugin Smart Marketing SMS and Newsletters Forms Security Bypass (2.6.1)