nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47932 CVE-2021-47932
CRITICAL
WordPress TheCartPress 1.5.3.6 Privilege Escalation Unauthenticated
Record summary
CVE-2021-47932 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to the tcp_register_and_login_ajax action with tcp_role set to administrator to gain full administrative access without authentication.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
TheCartPressBrowse thecartpress / TheCartPress | CVE List | Through 1.5.3.6 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWordpress Plugin TheCartPress 1.5.3.6 - Privilege Escalation (Unauthenticated)ExploitDB exploitby spacehenNot analyzed1 file
References
4Official Product Homepageproduct
https://wordpress.org/plugin/thecartpress ExploitDB-50378exploit
https://www.exploit-db.com/exploits/50378 VulnCheck Advisory: WordPress TheCartPress 1.5.3.6 Privilege Escalation UnauthenticatedThird-party advisory
https://www.vulncheck.com/advisories/wordpress-thecartpress-privilege-escalation-unauthenticated