.. / CVE-2021-24358

Exploit for Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirect (CVE-2021-24358)

Description:

WordPress Plus Addons for Elementor Page Builder before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an open redirect issue.

Nuclei Template

View the template here CVE-2021-24358.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-24358.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2021-24358
https://github.com/ARPSyndicate/kenzer-templates
https://wpscan.com/vulnerability/fd4352ad-dae0-4404-94d1-11083cb1f44d
https://theplusaddons.com/changelog/