ID | CVE-2021-4073 | ||||||
Sažetak | The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7. | ||||||
Reference |
|
||||||
CVSS |
|
||||||
Pristup |
|
||||||
Impact |
|
||||||
CVSS vektor | AV:N/AC:M/Au:N/C:P/I:P/A:P | ||||||
Zadnje važnije ažuriranje | 21-01-2022 - 20:58 | ||||||
Objavljeno | 14-12-2021 - 16:15 |