CVE-2021-25032: PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-25032?
The severity of CVE-2021-25032 is rated as medium due to its potential to allow unauthorized changes to plugin settings.
How do I fix CVE-2021-25032?
To fix CVE-2021-25032, upgrade the PublishPress Capabilities plugin to version 2.3.1 or later.
What versions of PublishPress Capabilities are affected by CVE-2021-25032?
CVE-2021-25032 affects all versions of PublishPress Capabilities before 2.3.1, including both the free and Pro versions.
What are the consequences of exploiting CVE-2021-25032?
Exploiting CVE-2021-25032 could allow an attacker to modify plugin settings without proper authorization.
Do I need to take additional security measures after fixing CVE-2021-25032?
Yes, it's recommended to review user permissions and implement security practices to mitigate future vulnerabilities.