VulnerabilityModified
CVE-2021-21389
The vulnerability has been fixed in BuddyPress 7.2.1.
HIGH 8.8EPSS 13.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.5%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 13.52% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- buddypress/buddypress
- Source
- security-advisories@github.com
References
- https://buddypress.org/2021/03/buddypress-7-2-1-security-release/Release Notes, Vendor Advisory
- https://codex.buddypress.org/releases/version-7-2-1/Release Notes, Vendor Advisory
- https://github.com/buddypress/BuddyPress/security/advisories/GHSA-m6j4-8r7p-wpp3Third Party Advisory
- https://buddypress.org/2021/03/buddypress-7-2-1-security-release/Release Notes, Vendor Advisory
- https://codex.buddypress.org/releases/version-7-2-1/Release Notes, Vendor Advisory
- https://github.com/buddypress/BuddyPress/security/advisories/GHSA-m6j4-8r7p-wpp3Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.