Record summary

CVE-2021-34622 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. .

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 28, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List3.0.0 - 3.1.3affected

Default status: unknown

CVE List, VulnCheck3.0.0 to ≤ 3.1.3affected

Nuclei templates

1
ProjectDiscoveryCRITICALWordPress ProfilePress <= 3.1.3 - Privilege EscalationCVSS 8.8

ProfilePress plugin before 3.1.4 allows privilege escalation. Due to insufficient validation in the profile update functionality, authenticated users can supply arbitrary usermeta fields, including `wp_capabilities`, during profile updates. This enables a user to escalate their privileges to administrator.

Impact

Authenticated users can escalate their privileges to administrator by supplying arbitrary usermeta fields during profile updates, leading to complete WordPress site takeover.

Remediation

Upgrade to ProfilePress version 3.1.4 or later.

WeaknessesCWE-269
AuthorsSourabh-Sahu
Template tagscvecve2021wordpresswp-pluginwpprofilepressprivilege-escalationauthenticatedintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:properfraction:profilepress:*:*:*:*:*:wordpress:*:*
FOFA: body="/wp-content/plugins/profilepress"

Source: ProjectDiscovery

References

2