vulnerability
WordPress Plugin: custom-registration-form-builder-with-submission-manager: CVE-2021-4073: Improper Authentication
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | Dec 8, 2021 | May 15, 2025 | Jul 9, 2025 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Dec 8, 2021
Added
May 15, 2025
Modified
Jul 9, 2025
Description
The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including administrators, if they knew a valid username on the site due to missing identity validation in the social login function social_login_using_email() of the plugin. This affects versions equal to, and less than, 5.0.1.7.
Solution
custom-registration-form-builder-with-submission-manager-plugin-cve-2021-4073
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.