{"api_version":"1","generated_at":"2026-07-23T14:02:06+00:00","cve":"CVE-2021-24803","urls":{"html":"https://cve.report/CVE-2021-24803","api":"https://cve.report/api/cve/CVE-2021-24803.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-24803","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-24803"},"summary":{"title":"CVE-2021-24803","description":"The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create another admin account and takeover the website via CSRF attacks","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2022-02-28 09:15:00","updated_at":"2022-03-07 18:11:00"},"problem_types":["CWE-352"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/97adac02-4163-48d4-ba14-0b1badfd3d42","name":"https://wpscan.com/vulnerability/97adac02-4163-48d4-ba14-0b1badfd3d42","refsource":"MISC","tags":[],"title":"Attention Required! | Cloudflare","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-24803","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-24803","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Francesco Carlucci","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"24803","vulnerable":"1","versionEndIncluding":"4.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"core_tweaks_wp_setup_project","cpe5":"core_tweaks_wp_setup","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2021-24803","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC","TITLE":"Core Tweaks WP Setup <= 4.1 - Arbitrary Admin Account Creation / Admin Email Update via CSRF"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","generator":"WPScan CVE Generator","affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"Core Tweaks WP Setup","version":{"version_data":[{"version_affected":"<=","version_name":"4.1","version_value":"4.1"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create another admin account and takeover the website via CSRF attacks"}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://wpscan.com/vulnerability/97adac02-4163-48d4-ba14-0b1badfd3d42","name":"https://wpscan.com/vulnerability/97adac02-4163-48d4-ba14-0b1badfd3d42"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"CWE-352 Cross-Site Request Forgery (CSRF)","lang":"eng"}]}]},"credit":[{"lang":"eng","value":"Francesco Carlucci"}],"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-02-28 09:15:00","lastModifiedDate":"2022-03-07 18:11:00","problem_types":["CWE-352"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:core_tweaks_wp_setup_project:core_tweaks_wp_setup:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"4.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"24803","Ordinal":"199565","Title":"CVE-2021-24803","CVE":"CVE-2021-24803","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"24803","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}