← Back to browse · API

CVE-2021-4073

Severity
CRITICAL
CVSS
9.8
EPSS
0.07
Risk score
41.65
CISA KEV
No
PoC
No
Published
2021-12-14
Modified
2025-02-14
First seen
2026-08-07
Aliases
EUVD-2021-33966, GHSA-3858-CVV4-QVJ7
Products
Metagauss:RegistrationMagic 5.0.1.7 ≤5.0.1.7
Sources
euvd EUVD-2021-33966

Description

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

References