vulnerability

WordPress Plugin: custom-registration-form-builder-with-submission-manager: CVE-2021-4073: Improper Authentication

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Dec 8, 2021
Added
May 15, 2025
Modified
May 15, 2025

Description

The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.

Solution

custom-registration-form-builder-with-submission-manager-plugin-cve-2021-4073
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.