Логотип exploitDog
bind:CVE-2021-21389
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-21389

Количество 2

Количество 2

nvd логотип

CVE-2021-21389

почти 5 лет назад

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

CVSS3: 8.1
EPSS: Критический
github логотип

GHSA-m6j4-8r7p-wpp3

больше 4 лет назад

BuddyPress privilege escalation via REST API

CVSS3: 8.1
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-21389

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

CVSS3: 8.1
93%
Критический
почти 5 лет назад
github логотип
GHSA-m6j4-8r7p-wpp3

BuddyPress privilege escalation via REST API

CVSS3: 8.1
93%
Критический
больше 4 лет назад

Уязвимостей на страницу