S4E just found a high-severity finding from cve-2001-1473 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 1, 2025

CVE-2021-4380 Scanner

CVE-2021-4380 Scanner - Unauthorized Admin Access vulnerability in Pinterest Automatic

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-4380
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on the 'wp_pinterest_automatic_parse_request' function and the 'process_form.php' script in versions up to, and including, 1.14.3. This makes it possible for unauthenticated attackers to update arbitrary options on a site that can be used to create new administrative user accounts or redirect unsuspecting site visitors.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Pinterest Automaticby ValvePress
0
Updated Aug 21, 2026View on NVD →
Detail

The Pinterest Automatic plugin is widely used on WordPress websites to automate the pinning of images from the site to Pinterest. It's typically employed by bloggers, digital marketers, and businesses looking to enhance their social media presence by systematically sharing content on Pinterest. The plugin is integrated directly into the WordPress ecosystem, allowing seamless management of Pinterest activities directly from the WordPress dashboard. Users can schedule pins, auto-publish from WordPress to Pinterest, and configure pin details such as descriptions and board locations. The plugin thus plays a crucial role in streamlining social media marketing efforts for many websites using WordPress. However, anything that bypasses user authentication settings can considerably elevate risks, as in the case with the unauthorized admin access vulnerability.

The unauthorized admin access vulnerability in Pinterest Automatic is significant due to its ability to bypass security measures that protect WordPress sites. This vulnerability, identified by CVE-2021-4380, results from insufficient capability checks within the plugin, allowing unauthorized modifications to site options. Exploiting such a flaw could enable attackers to update plugin settings without legitimate credentials. This type of vulnerability is particularly dangerous as it can result in unauthorized access and control over a website's administrative functions. It's crucial for users of the affected plugin versions to be aware of this vulnerability to mitigate potential risks it poses.

Technical exploration of this vulnerability revealed that the endpoints within the Pinterest Automatic plugin, specifically the `wp_pinterest_automatic_parse_request` function and `process_form.php`, lack sufficient authorization checks. HTTP requests can directly exploit these endpoints, enabling changes to be made in the website's options without any form of validation or checks on the user's authority to perform such actions. This lack of checks provides a clear path for attackers to perform unauthorized option updates. Additionally, crafting specific POST requests with the altered blog descriptions enables adversaries to redirect legitimate visitors or even create new administrative user accounts without detection.

If exploited, this vulnerability could allow malicious actors to gain administrative control over a WordPress site, thereby enabling them to execute arbitrary operations, including creating or deleting user accounts, altering website content, and redirecting site traffic. Such an attack could severely affect website integrity and lead to a breach of user trust, with further repercussions such as data theft or website defacement. The severity of this vulnerability underscores the importance of prompt remediation and updates to protect affected systems.

REFERENCES

Solution Advice
  • Upgrade the Pinterest Automatic plugin to version 4.14.4 or later to close the unauthorized admin access vulnerability.
  • Conduct a security audit of installed plugins to ensure no unauthorized options updates have been made.
  • Regularly review user roles and permissions to ensure they reflect current operational requirements and security policies.
  • Consider employing a web application firewall (WAF) to add a layer of security for potentially vulnerable endpoints.
  • Keep all WordPress plugins up-to-date to minimize exposure to known security vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-4380 Scanner - Unauthorized Admin Access vulnerability in Pinterest Automatic | S4E