vulnerability

WordPress Plugin: themeisle-companion: CVE-2021-24158: Improper Privilege Management

Severity
3
CVSS
(AV:N/AC:M/Au:S/C:N/I:P/A:N)
Published
Nov 24, 2020
Added
May 15, 2025
Modified
Jun 24, 2025

Description

Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default for users upon registration. This field is hidden from view for lower-level users, however, they can still supply the user_role parameter to update the default role for registration.

Solution

themeisle-companion-plugin-cve-2021-24158
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.