CVE-2021-24647
HIGH 8.1EPSS 9.8%
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
- CVSS v3.1
- 8.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P - EPSS
- 9.83% chance of exploitation in the next 30 days, 95th percentile
- Nuclei
- high · CWE-287
- Published
- 2021-11-08
- Updated
- 2024-08-03
Proof-of-concept exploits (2)
- https://wpscan.com/vulnerability/40d347b1-b86e-477d-b4c6-da105935ce37
- RandomRobbieBF/CVE-2021-246471★ · 2023-06-15