CE21 Suite
cpe:2.3:a:ce21:ce21_suite:*:*:*:*:wordpress:*:*
- >= 2.2.1, <= 2.3.1
A vulnerability exists in the CE21 Suite plugin for WordPress, specifically in versions 2.2.1 to 2.3.1. The issue arises from a missing capability check on the wp_ajax_nopriv_ce21_single_sign_on_save_api_settings AJAX action, allowing unauthorized users to update the plugin's API settings. This includes modifying a secret key used for authentication, which could enable the creation of new admin accounts on the affected site.
Exploitation of this vulnerability allows unauthenticated users to gain administrative privileges on the affected WordPress site by creating new admin accounts.
No known patch is available for this vulnerability. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.