Vulnerability record · CVE-2021-34621 · published 7 July 2021
CVE-2021-34621: ProfilePress WordPress plugin registration privilege escalation
Properfraction · Profilepress
The ProfilePress WordPress plugin's user registration component (RegistrationAuth.php) allows an attacker to register on a site as an administrator. The flaw is an improper privilege management and missing authentication issue affecting versions 3.0.0 through 3.1.3, and it is trivially reachable over the network without credentials.
Description
A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote privilege escalation to administrator with public exploit code and very high EPSS probability.
What it is
The ProfilePress WordPress plugin's user registration component (RegistrationAuth.php) allows an attacker to register on a site as an administrator. The flaw is an improper privilege management and missing authentication issue affecting versions 3.0.0 through 3.1.3, and it is trivially reachable over the network without credentials.
Impact
An unauthenticated attacker gains full administrative control of the affected WordPress site, enabling complete takeover including content, configuration and user management.
Attack surface
Reached over the network through the plugin's user registration endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Public exploit code is referenced by Packet Storm and Wordfence advisories, and EPSS is 0.68862 (99.3rd percentile), indicating high likelihood of exploitation; it is not listed in CISA KEV.
What to do
- Update the ProfilePress plugin to a version later than 3.1.3 immediately.
- If patching is not possible, disable or remove the plugin until it can be updated.
- Audit WordPress user accounts for unexpected administrator accounts created after exposure.
- Restrict or monitor access to the plugin's registration endpoints at the web server or WAF layer.
Detection
- Review WordPress user tables and logs for new administrator accounts created via registration.
- Monitor web server logs for POST requests to ProfilePress registration endpoints, especially from unexpected sources.
- Alert on plugin file changes or version checks indicating ProfilePress 3.0.0-3.1.3 remains installed.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/163973/WordPress-ProfilePress-3.1.3-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.wordfence.com/blog/2021/06/easily-exploitable-critical-vulnerabilities-patched-in-profilepress-plugin/ | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/163973/WordPress-ProfilePress-3.1.3-Privilege-Escalation.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.wordfence.com/blog/2021/06/easily-exploitable-critical-vulnerabilities-patched-in-profilepress-plugin/ | ExploitThird Party Advisory |
Track CVE-2021-34621 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-34621), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.