CVE-2021-4073: RegistrationMagic <= 5.0.1.7 Authentication Bypass
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function socialloginusingemail() of the plugin. This affects versions equal to, and less than, 5.0.1.7.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2021-4073.
What is the severity level of CVE-2021-4073?
The severity level of CVE-2021-4073 is critical (8.1).
Which software is affected by CVE-2021-4073?
The RegistrationMagic WordPress plugin, specifically the version up to 5.0.1.7, is affected by CVE-2021-4073.
What is the impact of CVE-2021-4073?
CVE-2021-4073 allows unauthenticated users to log in as any site user, including administrators, if they know a valid username on the site.
How can I fix CVE-2021-4073?
To fix CVE-2021-4073, update the RegistrationMagic WordPress plugin to a version that includes the patched vulnerability.