CVE-2021-4073

CRITICAL EXPLOITED NUCLEI

RegistrationMagic <5.0.1.7 - Auth Bypass

Title source: llm

Description

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

Nuclei Templates (1)

RegistrationMagic <= 5.0.1.7 - Authentication Bypass
CRITICALVERIFIEDby daffainfo

Scores

CVSS v3 9.8
EPSS 0.6888
EPSS Percentile 98.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2021-12-08
CWE
CWE-287
Status published
Products (1)
metagauss/registrationmagic < 5.0.1.7
Published Dec 14, 2021
Tracked Since Feb 18, 2026