← Vulnerability feed

Vulnerability record · CVE-2021-34621 · published 7 July 2021

CVE-2021-34621: ProfilePress WordPress plugin registration privilege escalation

Properfraction · Profilepress

The ProfilePress WordPress plugin's user registration component (RegistrationAuth.php) allows an attacker to register on a site as an administrator. The flaw is an improper privilege management and missing authentication issue affecting versions 3.0.0 through 3.1.3, and it is trivially reachable over the network without credentials.

9.8 CVSS 3.1 Critical EPSS 69% · top 0.7% CWE-269 · Improper privilege managementCWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 7.5
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the user registration component found in the ~/src/Classes/RegistrationAuth.php file of the ProfilePress WordPress plugin made it possible for users to register on sites as an administrator. This issue affects versions 3.0.0 - 3.1.3. .

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityUnauthenticated remote privilege escalation to administrator with public exploit code and very high EPSS probability.

What it is

The ProfilePress WordPress plugin's user registration component (RegistrationAuth.php) allows an attacker to register on a site as an administrator. The flaw is an improper privilege management and missing authentication issue affecting versions 3.0.0 through 3.1.3, and it is trivially reachable over the network without credentials.

Impact

An unauthenticated attacker gains full administrative control of the affected WordPress site, enabling complete takeover including content, configuration and user management.

Attack surface

Reached over the network through the plugin's user registration endpoint; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Public exploit code is referenced by Packet Storm and Wordfence advisories, and EPSS is 0.68862 (99.3rd percentile), indicating high likelihood of exploitation; it is not listed in CISA KEV.

What to do

  • Update the ProfilePress plugin to a version later than 3.1.3 immediately.
  • If patching is not possible, disable or remove the plugin until it can be updated.
  • Audit WordPress user accounts for unexpected administrator accounts created after exposure.
  • Restrict or monitor access to the plugin's registration endpoints at the web server or WAF layer.

Detection

  • Review WordPress user tables and logs for new administrator accounts created via registration.
  • Monitor web server logs for POST requests to ProfilePress registration endpoints, especially from unexpected sources.
  • Alert on plugin file changes or version checks indicating ProfilePress 3.0.0-3.1.3 remains installed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-34621 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-9947Properfraction profilepress improper authentication vulnerabilityThe ProfilePress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.11.1. This is due to insuffi…EPSS 0.53%9.8CVE-2021-34623Properfraction profilepress unrestricted file upload vulnerabilityA vulnerability in the image uploader component found in the ~/src/Classes/ImageUploader.php file of the ProfilePress WordPress plugin made it possib…EPSS 2.1%9.8CVE-2021-34624Properfraction profilepress unrestricted file upload vulnerabilityA vulnerability in the file uploader component found in the ~/src/Classes/FileUploader.php file of the ProfilePress WordPress plugin made it possible…EPSS 6.7%8.8CVE-2021-34622Properfraction profilepress improper privilege management vulnerabilityA vulnerability in the user profile update component found in the ~/src/Classes/EditUserProfile.php file of the ProfilePress WordPress plugin made it…EPSS 4.1%8.6CVE-2023-41954Properfraction profilepress improper privilege management vulnerabilityImproper Privilege Management vulnerability in ProfilePress Membership Team ProfilePress allows Privilege Escalation.This issue affects ProfilePress:…EPSS 1.2%7.5CVE-2023-44150Properfraction profilepress information exposure vulnerabilityExposure of Sensitive Information to an Unauthorized Actor vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registrat…EPSS 0.66%7.2CVE-2022-45083Properfraction profilepress deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, User Registration Form, Login Form…EPSS 0.58%6.1CVE-2024-1519Properfraction profilepress cross-site scripting vulnerabilityThe Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul…EPSS 0.57%

Source: NIST National Vulnerability Database (record CVE-2021-34621), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.