The Plus Addons for Elementor Page Builder < 4.1.10 - Open Redirect
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 2.3%
exploitation probability
2.3%top 18% of all CVEs
observed exploitation
nono source reports it
The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.10 did not validate a redirect parameter on a specifically crafted URL before redirecting the user to it, leading to an Open Redirect issue.
Affected products
Unknown · The Plus Addons for Elementor Page Builder