CVSS v3
8.1
HIGH
EPSS Score
57.7%
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.
Active exploitation of CVE-2021-4073 has not been confirmed. The EPSS score is 57.7%, indicating the estimated probability of exploitation in the next 30 days.
CVE-2021-4073 has a CVSS v3 base score of 8.1 (HIGH severity).
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
Ranked by exploit probability (EPSS).