CVE-2021-34621
CRITICAL 9.8EPSS 68.9%
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 68.86% chance of exploitation in the next 30 days, 99th percentile
- Nuclei
- critical
- Published
- 2021-07-07
- Updated
- 2024-10-15
Proof-of-concept exploits (4)
- http://packetstormsecurity.com/files/163973/WordPress-ProfilePress-3.1.3-Privilege-Escala…
- K3ysTr0K3R/CVE-2021-34621-EXPLOIT1★ · 2023-08-13
- RandomRobbieBF/CVE-2021-346210★ · 2023-08-09
- navreet1425/CVE-2021-346216★ · 2023-09-30