Lucene search

K
cveWPScanCVE-2021-24158
HistoryApr 05, 2021 - 7:15 p.m.

CVE-2021-24158

2021-04-0519:15:14
CWE-269
WPScan
web.nvd.nist.gov
23
2
orbit fox
themeisle
registration form
vulnerability
cve-2021-24158
user_role parameter

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

21.8%

Orbit Fox by ThemeIsle has a feature to add a registration form to both the Elementor and Beaver Builder page builders functionality. As part of the registration form, administrators can choose which role to set as the default for users upon registration. This field is hidden from view for lower-level users, however, they can still supply the user_role parameter to update the default role for registration.

Affected configurations

Nvd
Vulners
Node
themeisleorbit_foxRange<2.10.3wordpress
VendorProductVersionCPE
themeisleorbit_fox*cpe:2.3:a:themeisle:orbit_fox:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "product": "Orbit Fox by ThemeIsle",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "2.10.3",
        "status": "affected",
        "version": "2.10.3",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

21.8%

Related for CVE-2021-24158