Description
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.
No analysis available yet.
Remediation
Vendor Solution
Update to version 5.0.1.8, or newer.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-33966 | The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7. |
References
History
Fri, 14 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-02-14T17:48:49.176Z
Reserved: 2021-12-06T00:00:00.000Z
Link: CVE-2021-4073
Updated: 2024-08-03T17:16:03.759Z
Status : Modified
Published: 2021-12-14T16:15:09.833
Modified: 2024-11-21T06:36:51.040
Link: CVE-2021-4073
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD