CVE-2021-21389
BuddyPress privilege escalation via REST API
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.
BuddyPress es un plugin de WordPress de código abierto para crear un sitio comunitario. En versiones de BuddyPress de 5.0.0 versiones anteriores a 7.2.1, es posible para un usuario regular sin privilegios obtener derechos de administrador al explotar un problema en el endpoint de los miembros de la API REST. La vulnerabilidad ha sido corregida en BuddyPress versión 7.2.1. Las instalaciones existentes del plugin deben actualizarse a esta versión para mitigar el problema.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-22 CVE Reserved
- 2021-03-16 CVE Published
- 2021-05-31 First Exploit
- 2024-08-03 CVE Updated
- 2024-10-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/buddypress/BuddyPress/security/advisories/GHSA-m6j4-8r7p-wpp3 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/HoangKien1020/CVE-2021-21389 | 2021-05-31 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://buddypress.org/2021/03/buddypress-7-2-1-security-release | 2021-04-01 | |
https://codex.buddypress.org/releases/version-7-2-1 | 2021-04-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Buddypress Search vendor "Buddypress" | Buddypress Search vendor "Buddypress" for product "Buddypress" | >= 5.0.0 < 7.2.1 Search vendor "Buddypress" for product "Buddypress" and version " >= 5.0.0 < 7.2.1" | wordpress |
Affected
|