CVE-2021-47932Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting crafted requests to the AJAX handler. Attackers can send POST requests to the tcp_register_and_login_ajax action with tcp_role set to administrator to gain full administrative access without authentication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-10: 2Patch / Workaround · 2026-05-10: 1Technical Details · 2026-05-10: 205-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2021-47932 WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to create administrator accounts by submitting cra… https://www.cve.org/CVERecord?id=CVE-2021-47932

    Post summary

    The text announces an unauthenticated privilege‑escalation vulnerability in WordPress plugin TheCartPress 1.5.3.6 that allows attackers to create admin accounts. No PoC, exploit tool, patch, or active exploitation information is provided.

    0000070
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2021-47932 WordPress TheCartPress 1.5.3.6 contains an unauthenticated privilege escalation vulnerability that allows attackers to … CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2021-47932 #WordPress #CyberSecurity #InfoSec

    Post summary

    The alert announces a critical privilege‑escalation flaw (CVE‑2021‑47932) in TheCartPress 1.5.3.6, notes the lack of a patch, but does not provide a PoC, exploit, or evidence of active exploitation.

    0000032
    90 followersView on X

Explore more