CVE-2021-25032

Scores

EPSS

0.819high81.9%
0%20%40%60%80%100%

Percentile: 81.9%

CVSS

9.8critical3.x
0246810

CVSS Score: 9.8/10

All CVSS Scores

CVSS 3.x
9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS 2.0
7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Description

The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin’s settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-352

Exploits

Exploit ID: CVE-2021-25032

Source: github-poc

URL: https://github.com/RandomRobbieBF/CVE-2021-25032

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: capabilities

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:publishpress:capabilities:*:*:*:*:-:wordpress:*:*",      "versionEndExcluding": "2.3.1",      "vulnerable": true    },    {      "cpe23uri": ...

Source: nvd

End of list