← Back to browse · API

CVE-2021-4360

Severity
CRITICAL
CVSS
9.9
EPSS
0.01153
Risk score
40.0
CISA KEV
No
PoC
No
Published
2023-06-07
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2021-34187, GHSA-6P6C-8QQM-Q7CX
Products
waseem_senjer:Controlled Admin Access 0 <1.5.6
Sources
euvd EUVD-2021-34187

Description

The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access.

References