{"api_version":"1","generated_at":"2026-07-23T13:31:00+00:00","cve":"CVE-2021-4360","urls":{"html":"https://cve.report/CVE-2021-4360","api":"https://cve.report/api/cve/CVE-2021-4360.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-4360","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-4360"},"summary":{"title":"Controlled Admin Access < 1.5.6 - Privilege Escalation","description":"The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access.","state":"PUBLISHED","assigner":"Wordfence","published_at":"2023-06-07 02:15:14","updated_at":"2026-04-08 18:17:16"},"problem_types":["CWE-284","NVD-CWE-noinfo","CWE-284 CWE-284 Improper Access Control"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"security@wordfence.com","type":"Secondary","score":"9.9","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.9","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","data":{"baseScore":9.9,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://wpscan.com/vulnerability/5ddc0a9d-c081-4bef-aa87-3b10d037379c","name":"https://wpscan.com/vulnerability/5ddc0a9d-c081-4bef-aa87-3b10d037379c","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Controlled Admin Access < 1.5.6 - Improper Access Control to Privilege Escalation WordPress Security Vulnerability","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c57211a-f59d-4379-b09e-7c6049a6b04d?source=cve","name":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c57211a-f59d-4379-b09e-7c6049a6b04d?source=cve","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Controlled Admin Access < 1.5.6 - Privilege Escalation","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://plugins.svn.wordpress.org/controlled-admin-access/trunk/readme.txt","name":"https://plugins.svn.wordpress.org/controlled-admin-access/trunk/readme.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"403 Forbidden","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://blog.nintechnet.com/vulnerabilities-fixed-in-wordpress-controlled-admin-access-plugin/","name":"https://blog.nintechnet.com/vulnerabilities-fixed-in-wordpress-controlled-admin-access-plugin/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Vulnerabilities fixed in WordPress Controlled Admin Access plugin. – NinTechNet","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-4360","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-4360","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"waseem_senjer","product":"Controlled Admin Access","version":"affected 1.5.6 semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2021-03-30T00:00:00.000Z","lang":"en","value":"Disclosed"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Jerome Bruandet","lang":"en"}],"nvd_cpes":[{"cve_year":"2021","cve_id":"4360","vulnerable":"1","versionEndIncluding":"1.5.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wpruby","cpe5":"controlled_admin_access","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-03T17:23:10.684Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_transferred"],"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c57211a-f59d-4379-b09e-7c6049a6b04d?source=cve"},{"tags":["x_transferred"],"url":"https://blog.nintechnet.com/vulnerabilities-fixed-in-wordpress-controlled-admin-access-plugin/"},{"tags":["x_transferred"],"url":"https://plugins.svn.wordpress.org/controlled-admin-access/trunk/readme.txt"},{"tags":["x_transferred"],"url":"https://wpscan.com/vulnerability/5ddc0a9d-c081-4bef-aa87-3b10d037379c"}],"title":"CVE Program Container"},{"metrics":[{"other":{"content":{"id":"CVE-2021-4360","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2024-12-23T16:01:06.594687Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-12-23T16:21:35.790Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Controlled Admin Access","vendor":"waseem_senjer","versions":[{"lessThan":"1.5.6","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Jerome Bruandet"}],"descriptions":[{"lang":"en","value":"The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access."}],"metrics":[{"cvssV3_1":{"baseScore":9.9,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-04-08T17:05:58.363Z","orgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","shortName":"Wordfence"},"references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/8c57211a-f59d-4379-b09e-7c6049a6b04d?source=cve"},{"url":"https://blog.nintechnet.com/vulnerabilities-fixed-in-wordpress-controlled-admin-access-plugin/"},{"url":"https://plugins.svn.wordpress.org/controlled-admin-access/trunk/readme.txt"},{"url":"https://wpscan.com/vulnerability/5ddc0a9d-c081-4bef-aa87-3b10d037379c"}],"timeline":[{"lang":"en","time":"2021-03-30T00:00:00.000Z","value":"Disclosed"}],"title":"Controlled Admin Access < 1.5.6 - Privilege Escalation"}},"cveMetadata":{"assignerOrgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","assignerShortName":"Wordfence","cveId":"CVE-2021-4360","datePublished":"2023-06-07T01:51:29.828Z","dateReserved":"2023-06-06T12:53:52.550Z","dateUpdated":"2026-04-08T17:05:58.363Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2023-06-07 02:15:14","lastModifiedDate":"2026-04-08 18:17:16","problem_types":["CWE-284","NVD-CWE-noinfo","CWE-284 CWE-284 Improper Access Control"],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","baseScore":9.9,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.1,"impactScore":6},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wpruby:controlled_admin_access:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"1.5.5","matchCriteriaId":"B6FDF6FD-64C0-4EFD-8137-76072D0AB5A5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"4360","Ordinal":"1","Title":"Controlled Admin Access < 1.5.6 - Privilege Escalation","CVE":"CVE-2021-4360","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"4360","Ordinal":"1","NoteData":"The Controlled Admin Access plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1.5.5 by not properly restricting access to the configuration page. This makes it possible for attackers to create a new administrator role with unrestricted access.","Type":"Description","Title":"Controlled Admin Access < 1.5.6 - Privilege Escalation"}]}}}