S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2021-21389 Scanner

Detects 'Privilege Escalation' vulnerability in BuddyPress plugin for WordPress affects v. from 5.0.0 before 7.2.1.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-21389
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a non-privileged, regular user to obtain administrator rights by exploiting an issue in the REST API members endpoint. The vulnerability has been fixed in BuddyPress 7.2.1. Existing installations of the plugin should be updated to this version to mitigate the issue.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
BuddyPressby buddypress
>= 5.0.0, < 7.2.1
Updated Aug 21, 2026View on NVD →
Detail

BuddyPress is an open-source WordPress plugin that is designed to help individuals and organizations build and manage online communities. This user-friendly tool offers a wide range of features, including activity streams, user profiles, private messaging, group creation, and more. BuddyPress has become increasingly popular in recent years, particularly among nonprofit organizations and educational institutions.

However, despite its many benefits, BuddyPress has recently been discovered to have a security vulnerability. This vulnerability, identified as CVE-2021-21389, exists in releases of BuddyPress from 5.0.0 before version 7.2.1. The issue is related to the REST API members endpoint, which allows non-privileged, regular users to obtain administrator rights. This means that an attacker with access to a regular user account could effectively take control of the entire community site.

If this vulnerability is exploited, it can have serious consequences for both the community site and its users. An attacker could modify, delete, or steal sensitive data, hijack user accounts, and even inject malware into the site. This could have a devastating impact on the affected community, such as loss of trust, reputation damage, and financial losses.

At s4e.io, we offer pro features that can help you quickly and easily identify vulnerabilities in your digital assets. Our platform provides comprehensive security scans, vulnerability assessments, and threat intelligence reports that can help you stay ahead of potential threats. By taking proactive measures to protect your community site and its users, you can ensure that your online community remains a safe and secure space for everyone.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that can be taken to protect against this vulnerability. These include:

  • Updating BuddyPress to the latest version (7.2.1 or higher)
  • Limiting access to the REST API members endpoint
  • Enabling two-factor authentication for all user accounts
  • Regularly monitoring website activity and user behavior for suspicious activity
  • Utilizing a web application firewall to block malicious traffic

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.