CVE-2021-24647: Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
Other sources
The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24647?
CVE-2021-24647 is rated as a high severity vulnerability due to the potential for unauthenticated access to user accounts.
How do I fix CVE-2021-24647?
To fix CVE-2021-24647, update the Registration Forms plugin to version 3.1.7.6 or later.
Who is affected by CVE-2021-24647?
CVE-2021-24647 affects users of the Registration Forms plugin for WordPress versions prior to 3.1.7.6.
What type of vulnerability is CVE-2021-24647?
CVE-2021-24647 is a security flaw in the social login implementation that allows unauthorized access.
Can an attacker exploit CVE-2021-24647 without authentication?
Yes, an unauthenticated attacker can exploit CVE-2021-24647 to login as any user simply by knowing their username.