The Plus Addons for Elementor plugin (before version 4.1.7) allowed attackers to bypass authentication, gain admin access, and create accounts with elevated roles, even when registration was disabled and the Login widget was inactive.
id: CVE-2021-24175
info:
name: The Plus Addons for Elementor Page Builder < 4.1.7 - Authenticatio
...