CVE-2021-25032
Estado: ModificadaCrítica (9.8)—
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.69%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-352, CWE-862
- CWE-352, CWE-862
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-25032",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "contact@wpscan.com",
"affectedData": [
{
"vendor": "Unknown",
"product": "PublishPress Capabilities – User Role Access, Editor Permissions, Admin Menus",
"versions": [
{
"status": "affected",
"version": "2.0",
"lessThan": "2.0*",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.3.1",
"lessThan": "2.3.1",
"versionType": "custom"
}
]
},
{
"vendor": "Unknown",
"product": "PublishPress Capabilities Pro",
"versions": [
{
"status": "affected",
"version": "2.0",
"lessThan": "2.0*",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.3.1",
"lessThan": "2.3.1",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-01-10T16:15:08.847",
"references": [
{
"url": "https://plugins.trac.wordpress.org/changeset/2640161",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://wpscan.com/vulnerability/2f0f1a32-0c7a-48e6-8617-e0b2dcf62727",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "contact@wpscan.com"
},
{
"url": "https://plugins.trac.wordpress.org/changeset/2640161",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://wpscan.com/vulnerability/2f0f1a32-0c7a-48e6-8617-e0b2dcf62727",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "contact@wpscan.com",
"description": [
{
"lang": "en",
"value": "CWE-352"
},
{
"lang": "en",
"value": "CWE-862"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-352"
},
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role."
},
{
"lang": "es",
"value": "El plugin PublishPress Capabilities de WordPress versiones anteriores a 2.3.1, el plugin PublishPress Capabilities Pro de WordPress versiones anteriores a 2.3.1 no presentan comprobaciones de autorización y CSRF cuando es actualizada la configuración del plugin por medio del gancho init, y no se asegura de que las opciones que van a actualizarse pertenecen al plugin. Como resultado, atacantes no autenticados podrían actualizar opciones arbitrarias del blog, como el rol por defecto y hacer que cualquier nuevo usuario registrado tenga un rol de administrador"
}
],
"lastModified": "2026-06-17T03:41:20.697",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:publishpress:capabilities:*:*:*:*:-:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "1023AA29-D751-4A89-B9BA-F47ED50D4E97",
"versionEndExcluding": "2.3.1"
},
{
"criteria": "cpe:2.3:a:publishpress:capabilities:*:*:*:*:pro:wordpress:*:*",
"vulnerable": true,
"matchCriteriaId": "2739C8D6-5183-4299-BE1F-9F6D7165CE3F",
"versionEndExcluding": "2.3.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "contact@wpscan.com"
}