Vulnerability Description
The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create another admin account and takeover the website via CSRF attacks
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Core Tweaks Wp Setup Project | Core Tweaks Wp Setup | <= 4.1 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/97adac02-4163-48d4-ba14-0b1badfd3d42ExploitThird Party Advisory
- https://wpscan.com/vulnerability/97adac02-4163-48d4-ba14-0b1badfd3d42ExploitThird Party Advisory
FAQ
What is CVE-2021-24803?
CVE-2021-24803 is a vulnerability with a CVSS score of 8.8 (HIGH). The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in ...
How severe is CVE-2021-24803?
CVE-2021-24803 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-24803?
Check the references section above for vendor advisories and patch information. Affected products include: Core Tweaks Wp Setup Project Core Tweaks Wp Setup.