Unauthenticated Privilege Escalation in TheCartPress by WordPress
CVE-2021-47932
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 10 May 2026
Badges
What is CVE-2021-47932?
TheCartPress version 1.5.3.6 for WordPress contains a vulnerability that permits attackers to escalate privileges without authentication. By sending specially crafted POST requests to the AJAX handler, specifically through the tcp_register_and_login_ajax action with the tcp_role parameter set to administrator, an attacker can create a new administrator account. This exploit allows unauthorized users to gain full control over the WordPress site, leading to potential data breaches and various security risks.
Affected Version(s)
TheCartPress 0 <= 1.5.3.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved