K Elements <= 5.3.9 - Authentication Bypass

2025-02-17 00:00
Rafie Muhammad

Strategic Overview

Status
Patched in 5.4.0
Affected PluginK Elements
Affected Version<= 5.3.9
CVSS9.8Critical
CVECVE-2024-56000
View all K Elements vulnerabilities

Vulnerability Overview

The K Elements plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.3.9. This is due to the kleo_fb_intialize() function not having sufficient identity verification prior to authenticating a user. This makes it possible for unauthenticated attackers to log in as arbitrary users, granted they have access to their email.

Technical Analysis

REMEDIATION: Update to version 5.4.0, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C