CVE-2021-24158
WordPress vulnerability analysis and mitigation

Overview

CVE-2021-24158 is a privilege escalation vulnerability discovered in the Orbit Fox by ThemeIsle WordPress plugin versions prior to 2.10.3. The vulnerability was publicly disclosed on January 12, 2021, affecting sites with user registration enabled and either Elementor or Beaver Builder installed alongside Orbit Fox (WPScan).

Technical details

The vulnerability exists in the registration form feature of Orbit Fox that integrates with both Elementor and Beaver Builder page builders. While administrators can set default user roles for new registrations, the user_role parameter was accessible to lower-privileged users despite being hidden from view. The vulnerability has been assigned a CVSS score of 9.9 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, indicating its severe nature (Wordfence).

Impact

The vulnerability allows authenticated users with lower privileges to manipulate the default role setting for new user registrations, potentially creating new administrator accounts and completely compromising the affected WordPress site (WPScan).

Mitigation and workarounds

The vulnerability was patched in Orbit Fox version 2.10.3. Site administrators are strongly advised to update to this version or later to prevent potential exploitation (Wordfence).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13542CRITICAL9.8
  • designthemes-lms
NoYesDec 02, 2025
CVE-2025-13724HIGH7.5
  • vikrentcar
NoYesDec 02, 2025
CVE-2025-13731MEDIUM6.4
  • nexter-extension
NoYesDec 02, 2025
CVE-2025-12630MEDIUM4.9
  • upload-am-file-hosting-vpn
NoYesDec 02, 2025
CVE-2025-13090MEDIUM4.9
  • wpdirectorykit
NoYesDec 02, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management