S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Feb 23, 2024

CVE-2021-24647 Scanner

CVE-2021-24647 scanner - Unauthenticated Arbitrary Login vulnerability in Pie Register plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24647
8.1
CVSS

The Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes WordPress plugin before 3.1.7.6 has a flaw in the social login implementation, allowing unauthenticated attacker to login as any user on the site by only knowing their user ID or username

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Registration Forms – User profile, Content Restriction, Spam Protection, Payment Gateways, Invitation Codes
AFFECTED< 3.1.7.6SAFE ✓≥ 3.1.7.6
Updated Aug 21, 2026View on NVD →
Detail

Vulnerability Overview

Pie Register, a plugin for creating custom registration forms on WordPress, has a critical security flaw in its social login process. This flaw permits attackers to bypass authentication mechanisms, potentially logging in as any user by merely knowing their user ID or username.

Vulnerability Details

The issue lies within the social login functionality of Pie Register versions prior to 3.7.1.6. Specifically, an attacker can send a crafted POST request to the login URL with manipulated parameters (social_site=true and a user-defined user_id_social_site) to achieve unauthorized access to any user account.

Possible Effects

Successful exploitation allows an attacker to:

  • Access private user information.
  • Perform actions with the privileges of the compromised user, including administrative tasks.
  • Potentially escalate privileges or exploit further vulnerabilities within the site.

Why Choose S4E

S4E offers a comprehensive platform to detect vulnerabilities like CVE-2021-24647, providing users with:

  • Automated scanning tools designed for precision and efficiency.
  • Expert guidance on vulnerability remediation to secure your digital assets.
  • Access to a wide range of security resources and updates on the latest cyber threats. Joining S4E empowers you with the knowledge and tools needed to defend against sophisticated cyber attacks, ensuring the safety and integrity of your online presence.

References

Solution Advice
  • Immediate Update: Ensure the Pie Register plugin is updated to version 3.7.1.6 or later.
  • Review Logs: Check access logs for unusual login attempts or patterns that might indicate exploitation attempts.
  • Strengthen Authentication: Implement additional authentication measures such as two-factor authentication (2FA) for user accounts, especially administrators.
  • Regular Audits: Perform regular security audits and scans of your WordPress site to detect and mitigate new vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24647 scanner - Unauthenticated Arbitrary Login vulnerability in Pie Register plugin for WordPress | S4E