Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-4073

Опубликовано: 14 дек. 2021
Источник: nvd
CVSS3: 9.8
CVSS3: 8.1
CVSS2: 6.8
EPSS Средний

Описание

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:metagauss:registrationmagic:*:*:*:*:*:wordpress:*:*
Версия до 5.0.1.7 (включая)

EPSS

Процентиль: 98%
0.57717
Средний

9.8 Critical

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

github
около 4 лет назад

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

EPSS

Процентиль: 98%
0.57717
Средний

9.8 Critical

CVSS3

8.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-287