CVE-2025-11007
CE21 Suite 2.2.1 - 2.3.1 - Missing Authorization to Unauthenticated Privilege Escalation via Plugin Settings Update
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the wp_ajax_nopriv_ce21_single_sign_on_save_api_settings AJAX action in versions 2.2.1 to 2.3.1. This makes it possible for unauthenticated attackers to update the plugin's API settings including a secret key used for authentication. This allows unauthenticated attackers to create new admin accounts on an affected site.
| CWE | CWE-306 |
| Vendor | ce21com |
| Product | ce21 suite |
| Published | Nov 4, 2025 |
| Last Updated | Nov 4, 2025 |
Stay Ahead of the Next One
Get instant alerts for ce21com ce21 suite
Be the first to know when new critical vulnerabilities affecting ce21com ce21 suite are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
ce21com / CE21 Suite
2.2.1 โค 2.3.1
References
Credits
Kenneth Dunn