PT-2025-44916 · WordPress · Ce21 Suite
Kenneth Dunn
·
Published
2025-11-04
·
Updated
2025-11-04
·
CVE-2025-11007
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CE21 Suite versions 2.2.1 through 2.3.1
Description
The CE21 Suite plugin for WordPress is affected by an issue allowing unauthorized updates to plugin settings. A missing capability check on the
wp ajax nopriv ce21 single sign on save api settings AJAX action allows unauthenticated attackers to modify the plugin’s API settings, including a secret key used for authentication. Successful exploitation enables attackers to create new administrator accounts on a vulnerable site.Recommendations
Update CE21 Suite to a version later than 2.3.1.
Fix
LPE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ce21 Suite