Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2021-34622Improper Privilege Management in Profilepress

Severity
8.8HIGHNVD
VulnCheck9.8
EPSS
65.0%
top 1.52%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 7
Latest updateMay 24

Description

A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it possible for users to escalate their privileges to that of an administrator while editing their profile. This issue affects versions 3.0.0 - 3.1.3. .

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDproperfraction/profilepress3.0.03.1.3
CVEListV5profilepress/profilepress3.0.0 - 3.1.3

🔴Vulnerability Details

2
GHSA
GHSA-mfv5-8vh8-pcqg: A vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile2022-05-24
VulnCheck
ProfilePress WordPress plugin ~/src/Classes/EditUserProfile.php Priviledge Escalation Vulnerability2021

💥Exploits & PoCs

1
Nuclei
WordPress ProfilePress <= 3.1.3 - Privilege Escalation