← Back to CVE List

CVE-2021-4073

Published: 2021-12-14T16:15Z
Last Modified: 2024-11-21T06:36Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt