K Elements <= 5.3.9 - Authentication Bypass
2025-02-17 00:00
Rafie MuhammadStrategic Overview
StatusPatched in 5.4.0
Affected PluginK Elements
Affected Version
<= 5.3.9CVSS9.8Critical
CVE
CVE-2024-56000Vulnerability Overview
The K Elements plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.3.9. This is due to the kleo_fb_intialize() function not having sufficient identity verification prior to authenticating a user. This makes it possible for unauthenticated attackers to log in as arbitrary users, granted they have access to their email.
Technical Analysis
REMEDIATION: Update to version 5.4.0, or a newer patched version --- IDENTIFIER: CWE-266 (Incorrect Privilege Assignment) A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C