HIGH

CVE-2021-4073

CVSS v3

8.1

HIGH

EPSS Score

57.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

Technical details

Published
12/14/2021

Frequently asked questions

What is CVE-2021-4073?

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

Is CVE-2021-4073 actively exploited?

Active exploitation of CVE-2021-4073 has not been confirmed. The EPSS score is 57.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-4073?

CVE-2021-4073 has a CVSS v3 base score of 8.1 (HIGH severity).

Is CVE-2021-4073 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.